CVE-2020-10818: OS Command Injection
Published Mar 22, 2020
·Updated
Artica Proxy 4.26 allows remote command execution for an authenticated user via shell metacharacters in the "Modify the hostname" field.
Affected Software
1 affected component
Articatech Artica Proxy=4.26
Event History
Mar 22, 2020
CVE Published
via MITRE·07:53 PM
Data Sourced
via MITRE·07:53 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10818?
CVE-2020-10818 has a high severity rating due to its potential for remote command execution.
2
How do I fix CVE-2020-10818?
To fix CVE-2020-10818, update Artica Proxy to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2020-10818?
Any instance of Artica Proxy version 4.26 is affected by CVE-2020-10818.
4
What happens if I am exploited through CVE-2020-10818?
Exploitation of CVE-2020-10818 could allow an authenticated user to execute arbitrary commands on the server.
5
Is there a workaround for CVE-2020-10818?
A temporary workaround for CVE-2020-10818 is to restrict access to the modification settings for the hostname.