CVE-2020-13159: Command Injection
Published Jun 22, 2020
·Updated
Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclientmac, Hostname, or Alias field. NOTE: this may overlap CVE-2020-10818.
Affected Software
1 affected component
Articatech Artica Proxy<4.30.000000
Event History
Jun 22, 2020
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-13159?
CVE-2020-13159 is classified as a high-severity vulnerability due to the potential for OS command injection.
2
How do I fix CVE-2020-13159?
To fix CVE-2020-13159, upgrade to Artica Proxy version 4.30.000001 or later.
3
What are the affected versions for CVE-2020-13159?
CVE-2020-13159 affects Artica Proxy versions prior to 4.30.000000.
4
What are the potential impacts of CVE-2020-13159?
Exploitation of CVE-2020-13159 can lead to unauthorized OS command execution on the affected system.
5
Which fields can lead to exploitation of CVE-2020-13159?
The fields that may allow for exploitation of CVE-2020-13159 include Netbios name, Server domain name, dhclient_mac, Hostname, or Alias.