vendor:
Osprey Pump Controller
by:
LiquidWorm
7.5
CVSS
HIGH
Semi-blind Command Injection
78
CWE
Product Name: Osprey Pump Controller
Affected Version From: Software Build ID 20211018, Production 10/18/2021
Affected Version To: Mirage App: MirageAppManager, Release [1.0.1]
Patch Exists: No
Related CWE:
CPE: a:propump_and_controls:osprey_pump_controller:1.0.1
Platforms Tested:
2021
Osprey Pump Controller 1.0.1 – (pseudonym) Semi-blind Command Injection
ProPump & Controls' Osprey Pump Controller 1.0.1 is vulnerable to a semi-blind command injection vulnerability. This vulnerability allows an attacker to inject arbitrary commands into the system without authentication. The vulnerability exists due to the lack of proper input validation when handling user-supplied data. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious commands.
Mitigation:
ProPump & Controls should implement proper input validation when handling user-supplied data.