Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL.
References
Link | Resource |
---|---|
https://github.com/Fadavvi/CVE-2018-17431-PoC#confirmation-than-bug-exist-2018-09-25-ticket-id-xwr-503-79437 | Exploit Third Party Advisory |
https://drive.google.com/file/d/0BzFJhNQNHcoTbndsUmNjVWNGYWNJaWxYcWNyS2ZDajluTDFz/view | Permissions Required Third Party Advisory |
http://packetstormsecurity.com/files/159246/Comodo-Unified-Threat-Management-Web-Console-2.7.0-Remote-Code-Execution.html | Exploit Third Party Advisory VDB Entry |
Configurations
Information
Published : 2019-01-30 07:29
Updated : 2023-01-20 07:35
NVD link : CVE-2018-17431
Mitre link : CVE-2018-17431
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
comodo
- unified_threat_management_firewall