First published: Tue Jan 03 2023(Updated: )
ChangingTec ServiSign component has insufficient filtering for special characters in the connection response parameter. An unauthenticated remote attacker can host a malicious website for the component user to access, which triggers command injection and allows the attacker to execute arbitrary system command to perform arbitrary system operation or disrupt service.
Credit: twcert@cert.org.tw twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
ChangingTec ServiSign | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.