Multiple Infoblox Network Automation Products CVE-2014-3418 OS Command Injection Vulnerability
BID:68471
Info
Multiple Infoblox Network Automation Products CVE-2014-3418 OS Command Injection Vulnerability
| Bugtraq ID: | 68471 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3418 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2014 12:00AM |
| Updated: | Jul 09 2014 12:00AM |
| Credit: | Nate Kettlewell of Depth Security. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Multiple Infoblox Network Automation Products CVE-2014-3418 OS Command Injection Vulnerability
Multiple Infoblox Network Automation Products including NetMRI, Switch Port Manager, Automation Change Manager and Security Device Controller are prone to an OS command-injection vulnerability.
Successfully exploiting this issue may allow an attacker to execute arbitrary OS commands in the context of the affected application.
Multiple Infoblox Network Automation Products including NetMRI, Switch Port Manager, Automation Change Manager and Security Device Controller are prone to an OS command-injection vulnerability.
Successfully exploiting this issue may allow an attacker to execute arbitrary OS commands in the context of the affected application.
Exploit / POC
Multiple Infoblox Network Automation Products CVE-2014-3418 OS Command Injection Vulnerability
Attackers can exploit this issue using browser or readily available tools.
Attackers can exploit this issue using browser or readily available tools.
Solution / Fix
Multiple Infoblox Network Automation Products CVE-2014-3418 OS Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple Infoblox Network Automation Products CVE-2014-3418 OS Command Injection Vulnerability
References:
References:
- NetMRI Homepage (Infoblox)
- NetMRI-CVE-2014-3418 - Metasploit Module (Nate Kettlewell)