CVE-2020-19907: OS Command Injection
A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-19907?
CVE-2020-19907 is a command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier that allows authenticated attackers to execute any command or service.
How severe is CVE-2020-19907?
CVE-2020-19907 has a severity rating of 8.8, which is considered high.
Which software versions are affected by CVE-2020-19907?
Caldera versions up to and including 2.3.1 are affected by CVE-2020-19907.
How can authenticated attackers exploit CVE-2020-19907?
Authenticated attackers can exploit CVE-2020-19907 by injecting malicious commands or services through the sandcat plugin.
Are there any references for CVE-2020-19907?
Yes, you can find references for CVE-2020-19907 at the following URLs: [https://cwe.mitre.org/data/definitions/78.html](https://cwe.mitre.org/data/definitions/78.html) and [https://github.com/mitre/caldera/issues/462](https://github.com/mitre/caldera/issues/462)