An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec(), cmd_sys_arp_clear(), and cmd_sys_ping_exec() functions in the libclicmd.so library contained in the firmware, an attacker could leverage these functions to call system() and execute arbitrary commands on the switches. (Note that these functions are currently not called in this version of the firmware, however an attacker could use other vulnerabilities to finally use these vulnerabilities to gain code execution.)
Project Subscriptions
| Vendors | Products |
|---|---|
|
Zyxel
Subscribe
|
Gs1900-10hp
Subscribe
Gs1900-10hp Firmware
Subscribe
Gs1900-16
Subscribe
Gs1900-16 Firmware
Subscribe
Gs1900-24
Subscribe
Gs1900-24 Firmware
Subscribe
Gs1900-24e
Subscribe
Gs1900-24e Firmware
Subscribe
Gs1900-24hp
Subscribe
Gs1900-24hp Firmware
Subscribe
Gs1900-48
Subscribe
Gs1900-48 Firmware
Subscribe
Gs1900-48hp
Subscribe
Gs1900-48hp Firmware
Subscribe
Gs1900-8
Subscribe
Gs1900-8 Firmware
Subscribe
Gs1900-8hp
Subscribe
Gs1900-8hp Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-6719 | An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec(), cmd_sys_arp_clear(), and cmd_sys_ping_exec() functions in the libclicmd.so library contained in the firmware, an attacker could leverage these functions to call system() and execute arbitrary commands on the switches. (Note that these functions are currently not called in this version of the firmware, however an attacker could use other vulnerabilities to finally use these vulnerabilities to gain code execution.) |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T00:56:22.476Z
Reserved: 2019-08-29T00:00:00.000Z
Link: CVE-2019-15800
No data.
Status : Modified
Published: 2019-11-14T21:15:11.687
Modified: 2024-11-21T04:29:29.487
Link: CVE-2019-15800
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD