Several OS command injection vulnerabilities exist in the...
Critical severity
Unreviewed
Published
Jan 27, 2023
to the GitHub Advisory Database
•
Updated Feb 6, 2023
Description
Published by the National Vulnerability Database
Jan 26, 2023
Published to the GitHub Advisory Database
Jan 27, 2023
Last updated
Feb 6, 2023
Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is reachable through the m2m's DOWNLOAD_INFO command.
References