First published: Mon Jul 12 2021(Updated: )
A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MITRE CALDERA | <=2.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-19907 is a command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier that allows authenticated attackers to execute any command or service.
CVE-2020-19907 has a severity rating of 8.8, which is considered high.
Caldera versions up to and including 2.3.1 are affected by CVE-2020-19907.
Authenticated attackers can exploit CVE-2020-19907 by injecting malicious commands or services through the sandcat plugin.
Yes, you can find references for CVE-2020-19907 at the following URLs: [https://cwe.mitre.org/data/definitions/78.html](https://cwe.mitre.org/data/definitions/78.html) and [https://github.com/mitre/caldera/issues/462](https://github.com/mitre/caldera/issues/462)