CVE-2020-8858: Moxa MGate 5105-MB-EIP DestIP Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Moxa MGate 5105-MB-EIP firmware version 4.1. Authentication is required to exploit this vulnerability. The specific flaw exists within the DestIP parameter within MainPing.asp. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9552.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Moxa MGate 5105-MB-EIPto a version that resolves this vulnerability.Fixed in 4.1Patch ZDI-CAN-9552
Event History
Frequently Asked Questions
What is the severity of CVE-2020-8858?
CVE-2020-8858 has a high severity rating due to the potential for remote code execution by authenticated attackers.
How do I fix CVE-2020-8858?
To fix CVE-2020-8858, update the Moxa MGate 5105-MB-EIP firmware to the latest version beyond 4.1.
What products are affected by CVE-2020-8858?
CVE-2020-8858 affects Moxa MGate 5105-MB-EIP devices running firmware version 4.1.
Is authentication required to exploit CVE-2020-8858?
Yes, authentication is required to exploit the vulnerability identified in CVE-2020-8858.
What is the main issue in CVE-2020-8858?
The main issue in CVE-2020-8858 exists within the DestIP parameter in MainPing.asp, allowing for arbitrary code execution.