vendor:
BadBlue
by:
Unknown
7.5
CVSS
HIGH
Input Validation
Unknown
CWE
Product Name: BadBlue
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:xcellenet:badblue
Platforms Tested: Windows
Unknown
BadBlue Remote Unauthorized Access Vulnerability
The vulnerability is caused by an input validation issue in the 'ext.dll' component of BadBlue. A remote attacker can exploit this vulnerability by sending a specially crafted request to the server. By causing '.hts' files to be interpreted by the server, the attacker can execute administrative commands without authorization.
Mitigation:
Apply the latest patches and updates provided by the vendor. Restrict access to the affected component from untrusted networks.