vendor:
1754 GCM Family
by:
Alex A. Bravo
8,8
CVSS
HIGH
Remote Code Execution and Arbitrary File Read
78, 22
CWE
Product Name: 1754 GCM Family
Affected Version From: v1.20.0.22575
Affected Version To: v1.20.0.22575
Patch Exists: YES
Related CWE: CVE-2014-2085, CVE-2014-3081
CPE: h:ibm:1754_gcm_family
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
Remote Code Execution and Arbitrary File Read in IBM 1754 GCM Family
Improperly sanitized input may allow a remote authenticated attacker to perform remote code execution on the GCM KVM switch. This device also allows any authenticated user to read arbitrary files. Files can be anywhere on the target.
Mitigation:
Ensure that all input is properly sanitized and that access to the device is restricted to only authorized users.