← Back

CVE-2018-16232

nvd nist
Published: Oct 17, 2018Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi. This allows an authenticated user with privileges for the affected page to execute arbitrary commands.

Affected (56)

Products: Ipfire: Ipfire
1 product
Ipfire
Configuration A
56 vulnerable
Vulnerable SoftwareAffected Versions
Ipfire
Version 1.49
Version 2.11 core_update53
Version 2.11 core_update54
Version 2.11 core_update59
Version 2.11 core_update60
Version 2.11 core_update62
Version 2.11 core_update64
Version 2.13 core_update66
Version 2.13 core_update67
Version 2.13 core_update71
Version 2.13 core_update72
Version 2.13 core_update73
Version 2.13 core_update74
Version 2.13 core_update75
Version 2.13 core_update76
Version 2.13 rc_1
Version 2.13 rc_2
Version 2.15 76_rc1
Version 2.15 77_rc1
Version 2.15 77_rc2
Version 2.15 core_update79
Version 2.15 core_update81
Version 2.15 core_update82
Version 2.15 core_update83
Version 2.15 core_update84
Version 2.15 core_update85
Version 2.17 86_beta1
Version 2.17 87_rc1
Version 2.17 core_update88
Version 2.17 core_update89
Version 2.17 core_update91
Version 2.17 core_update93
Version 2.17 core_update95
Version 2.17 core_update97
Version 2.17 core_update98
Version 2.17 core_update99
Version 2.19 core_update100
Version 2.19 core_update101
Version 2.19 core_update102
Version 2.19 core_update105
Version 2.19 core_update106
Version 2.19 core_update107
Version 2.19 core_update108
Version 2.19 core_update111
Version 2.19 core_update112
Version 2.19 core_update113
Version 2.19 core_update114
Version 2.19 core_update116
Version 2.19 core_update117
Version 2.19 core_update118
Version 2.19 core_update119
Version 2.19 core_update120
Version 2.1
Version 2.1 core_update16
Version 2.21 core_update122
Version 2.21 core_update123

References (4)

Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.