vendor:
WAS-Scanner
by:
Sameer Goyal
7.8
CVSS
HIGH
Remote Command Execution (RCE)
78
CWE
Product Name: WAS-Scanner
Affected Version From: WAS-20180328
Affected Version To: WAS-20180328
Patch Exists: YES
Related CWE: N/A
CPE: a:tenable:was-scanner
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: CentOS 7.4.1708
2018
Tenable WAS-Scanner 7.4.1708 – Remote Command Execution
Setup a malicious DHCP server in the network using dnsmasq, start a listener on port 5555 on other terminal, send a normal IP request to the malicious DHCP server from the victim machine and check the listener to get the reverse shell with root privileges.
Mitigation:
Disable NetworkManager daemon or restrict access to it.