Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106380
Category:Web application abuses
Title:op5 Monitor < 7.1.19 RCE Vulnerability
Summary:op5 Monitor is prone to a remote command execution (RCE); vulnerability.
Description:Summary:
op5 Monitor is prone to a remote command execution (RCE)
vulnerability.

Vulnerability Insight:
op5 Monitor has a CSRF entry point that can be used to execute
arbitrary remote commands on op5 system sent via HTTP GET requests, allowing attackers to
completely takeover the affected host, to be victimized a user must be authenticated and visit a
malicious webpage or click an infected link.

Vulnerability Impact:
An authenticated attacker execute arbitrary commands.

Affected Software/OS:
op5 Monitor versions 7.1.19 and prior.

Solution:
Update to version 7.2.0 or later.

CVSS Score:
9.0

CVSS Vector:
AV:N/AC:L/Au:S/C:C/I:C/A:C

CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.