vendor:
QNX Neutrino RTOS
by:
Mor!p3r
7,5
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: QNX Neutrino RTOS
Affected Version From: QNX 6.5.0 >=
Affected Version To: QCONN >= 1.4.207944
Patch Exists: YES
Related CWE: N/A
CPE: o:qnx:qnx_neutrino_rtos
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012
QNX QCONN Remote Command Execution Vurnerability
This exploit allows an attacker to execute arbitrary commands on a vulnerable QNX QCONN system. The exploit is triggered by sending a specially crafted telnet request to the target system. The request contains a command to launch the 'shutdown' command, which will cause the system to reboot.
Mitigation:
The vendor has released a patch to address this vulnerability.