vendor:
IrisAccess ICU 7000-2
by:
N/A
9,8
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: IrisAccess ICU 7000-2
Affected Version From: ICU Software: 1.00.08, ICU OS: 1.3.8, ICU File system: 1.3.8, EIF Firmware [Channel 1]: 1.9, EIF Firmware [Channel 2]: 1.9, Iris TwoPi: 1.4.5
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: h:iris_id:irisaccess_icu_7000-2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: LINUX
2020
Iris ID IrisAccess ICU 7000-2 Remote Root Command Execution
The Iris ID IrisAccess ICU 7000-2 device suffers from an unauthenticated remote command execution vulnerability. The vulnerability exist due to several POST parameters in the '/html/SetSmarcardSettings.php' script not being sanitized when using the exec() PHP function while updating the Smart Card Settings on the affected device. Calling the '$CommandForExe' variable which is set to call the '/cgi-bin/setsmartcard' CGI binary with the affected parameters as arguments allows the attacker to execute arbitrary system commands as the root user and bypass the biometric access control in place.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to update the affected device to the latest version.