vendor:
Easywall
by:
Melvin Mejia
6.1
CVSS
HIGH
Authenticated Remote Command Execution
78
CWE
Product Name: Easywall
Affected Version From: 36586
Affected Version To: 36586
Patch Exists: NO
Related CWE: CVE-XXXX-XXXX (Not provided in the text)
CPE: a:easywall_project:easywall:0.3.1
Platforms Tested: Ubuntu 22.04
2023
Easywall 0.3.1 – Authenticated Remote Command Execution
The Easywall 0.3.1 software is prone to an authenticated remote command execution vulnerability. By exploiting this issue, a remote attacker who has authenticated access to the application can execute arbitrary commands on the target system. This can lead to complete compromise of the system.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of the software when available. Additionally, restrict network access to the application and ensure that strong, unique passwords are used for authentication.