vendor:
Osprey Pump Controller
by:
LiquidWorm
9.8
CVSS
CRITICAL
Command Injection
78
CWE
Product Name: Osprey Pump Controller
Affected Version From: Software Build ID 20211018, Production 10/18/2021
Affected Version To: Mirage App: MirageAppManager, Release [1.0.1]
Patch Exists: YES
Related CWE: CVE-2021-27092
CPE: cpe:a:propump_and_controls:osprey_pump_controller:1.0.1
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=148468, https://www.infosecmatter.com/nessus-plugin-library/?id=58141, https://www.infosecmatter.com/nessus-plugin-library/?id=35409, https://www.infosecmatter.com/nessus-plugin-library/?id=35421, https://www.infosecmatter.com/nessus-plugin-library/?id=107968
Platforms Tested: Windows, Linux, Mac
2021
Osprey Pump Controller 1.0.1 – (eventFileSelected) Command Injection
A command injection vulnerability exists in ProPump and Controls Osprey Pump Controller 1.0.1. An attacker can exploit this vulnerability by sending a specially crafted eventFileSelected request to the vulnerable application. This can allow the attacker to execute arbitrary commands on the underlying operating system.
Mitigation:
Upgrade to the latest version of the Osprey Pump Controller.