vendor:
LinuxKI
by:
Cody Winkler
9.8
CVSS
CRITICAL
Remote Command Injection
78
CWE
Product Name: LinuxKI
Affected Version From: <= v6.0-1
Affected Version To: <= v6.0-1
Patch Exists: YES
Related CWE: CVE-2020-7209
CPE: a:hewlett_packard:linuxki:6.0-1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: LinuxKI Docker Image
2020
HP LinuxKI 6.01 – Remote Command Injection
HP LinuxKI is vulnerable to a remote command injection vulnerability due to insufficient sanitization of user-supplied input. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable server. This can allow the attacker to execute arbitrary commands on the vulnerable system.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of HP LinuxKI.