ZeroHour

CVE-2018-16232

PoC
CVSS 3.1
8.8 high
EPSS
8%p94
Published
()
Modified
Description

An authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi. This allows an authenticated user with privileges for the affected page to execute arbitrary commands.

Vendors
ipfire
Products
ipfire
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.