vendor:
Osprey Pump Controller
by:
LiquidWorm
9.8
CVSS
CRITICAL
Blind Command Injection
78
CWE
Product Name: Osprey Pump Controller
Affected Version From: Software Build ID 20211018, Production 10/18/2021
Affected Version To: Mirage App: MirageAppManager, Release [1.0.1]
Patch Exists: YES
Related CWE: CVE-2021-27092
CPE: a:propump_and_controls:osprey_pump_controller:1.0.1
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=148468, https://www.infosecmatter.com/nessus-plugin-library/?id=58141, https://www.infosecmatter.com/nessus-plugin-library/?id=35409, https://www.infosecmatter.com/nessus-plugin-library/?id=35421, https://www.infosecmatter.com/nessus-plugin-library/?id=107968
Platforms Tested:
2021
Osprey Pump Controller 1.0.1 – (userName) Blind Command Injection
A vulnerability in ProPump and Controls' Osprey Pump Controller 1.0.1 allows an unauthenticated attacker to inject arbitrary commands into the userName parameter of the web application. This can be exploited to execute arbitrary commands with the privileges of the web server process.
Mitigation:
ProPump and Controls has released a patch to address this vulnerability.