CVE-2018-14417
SoftNAS Cloud < 4.0.3 - OS Command Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary commands with root permissions.
Se ha encontrado una vulnerabilidad de inyección de comandos en la consola de administración web en SoftNAS Cloud en versiones anteriores a la 4.0.3. En particular, el script snserv no saneó el parámetro "recentVersion" desde el endpoint snserv, lo que permite que un atacante no autenticado ejecute comandos arbitrarios con permisos root.
SoftNAS Cloud versions prior to 4.0.3 suffers from an OS command injection vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-07-19 CVE Reserved
- 2018-07-27 CVE Published
- 2018-07-27 First Exploit
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/104914 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/148718 | 2018-07-27 | |
https://www.exploit-db.com/exploits/45097 | 2024-08-05 | |
http://seclists.org/fulldisclosure/2018/Jul/85 | 2024-08-05 | |
https://www.coresecurity.com/advisories/softnas-cloud-os-command-injection | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://docs.softnas.com/display/SD/Release+Notes | 2018-10-02 |