Description
Some payload elements of the messages sent between two stations in a networking architecture are not properly checked on the receiving station allowing an attacker to execute unauthorized commands in the application.
Problem types
CWE-940 Improper Verification of Source of a Communication Channel
CWE-1288 Improper Validation of Consistency within Input
Product status
16.0 (cpe) before 16.3.1
15.0 (cpe) before 15.2.12
12.0 (cpe) before 12.0.31
Credits
Guillaume André (Synacktiv)
Pierre Gertner (Synacktiv)
References
www.pcvue.com/security/