vendor:
Wireless Appliance
by:
N/A
7,2
CVSS
HIGH
Shell Escape via `less` command
78
CWE
Product Name: Wireless Appliance
Affected Version From: < 5.1.8
Affected Version To: 5.1.8
Patch Exists: YES
Related CWE: CVE-2017-11321
CPE: a:ucopia:wireless_appliance
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: SSH, ShellInTheBox
2017
[CVE-2017-11321] UCOPIA Wireless Appliance < 5.1.8 Restricted Shell Escape
Improper sanitization of system commands in the restricted shell interface in UCOPIA Wireless Appliance, prior to 5.1.8, allows remote attackers to gain access to a system shell as the "admin" user. By logging in within these interfaces, we can access to a restricted shell (*clish*) that allows only a few commands. However, the `less` command is allowed, and because `less` allows to execute shell commands when viewing a file, we can use it to escape the restricted shell.
Mitigation:
Update to Ucopia Wireless Appliance version 5.1.8 or later.