Description
MiR software versions prior to version 3.0.0 are affected by a command injection vulnerability. A malicious HTTP request crafted by an authenticated user could allow the execution of arbitrary commands on the underlying operating system.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
Any version before 3.0.0
Any version before 3.0.0
Credits
Lockheed Martin Red Team
References
mobile-industrial-robots.com/...advisories/command-injection
supportportal.mobile-industrial-robots.com/...ecurity-guide/