Advisory ID | NN-2021:1-01 |
---|---|
Topic | Authenticated command injection when changing date settings or hostname in Guardian/CMC before 20.0.7.4 |
Impact | Code Execution, Gain Privileges, CWE-78 OS Command Injection |
Issue date | 2021-02-04 |
Affects | Guardian and CMC with N2OS <v20.0.7.4 or N2OS <v19.0.12 |
CVE Name(s) | CVE-2021-26724 |
CVSS Score | 7.2 |
CVE Risk Level | High |
Risk Level for Nozomi customers | Low |
An OS command injection vulnerability in the management interface allows an authenticated administrator to execute arbitrary OS commands gaining access to the system.
Authenticated web GUI administrator can execute a command on the local system and then escalate privilege to the root user.
However, as by design web GUI administrators are allowed to use ssh keys to gain full console access, this finding has a low impact on our customers.
Guardian / CMC before v19.0.12.
Guardian / CMC before v20.0.7.4.
Use internal firewall feature to limit management interface access and review user roles.
v19 series: Upgrade to v19.0.12.
v20 series: Upgrade to v20.0.7.4.
2021-02-22: Initial revision
This bug was found by Erik de Jong