QID 730258
Date Published: 2021-11-18
QID 730258: rConfig OS Command Injection Vulnerability
rConfig is an open source network device configuration management utility for network engineers to take frequent configuration snapshots of their network devices.
Affected Versions:
rConfig 3.9.4 and prior
QID Detection Logic:
This signature checks for the vulnerable versions of rConfig in the HTTP GET request.
Allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter.
Solution
Vendor has released a patch to address this issue. Customers are advised to refer to rConfig release notes for updates pertaining to this vulnerability.
Vendor References
- rConfig release notes -
www.rconfig.com/downloads/v3-release-notes
CVEs related to QID 730258
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2020-10221 |
|