Description
SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e.
Problem types
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Product status
Any version
Credits
P. Chistè
A. Falb
M. Selinger
M. Suchy
P. Oberndorfer
P. Maluenda
D. Sagl
M. Narbeshuber-Spletzer
J. Springer
P. Riedl
C. Hierzer
M. Pammer
References
cyberdanube.com/...as-multiple-vulnerabilities-in-oring-iap/