CVE-2018-7084
published 2019-05-10CVE-2018-7084: A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary system…
PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.63%
90.6th percentile
A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary system commands within the underlying operating system. An attacker could use this ability to copy files, read configuration, write files, delete files, or reboot the device. Workaround: Block access to the Aruba Instant web interface from all untrusted users. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.1
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arubanetworks | aruba_instant | >= 4.0 < 4.2.4.12 | 4.2.4.12 |
| arubanetworks | aruba_instant | >= 6.5.0 < 6.5.4.11 | 6.5.4.11 |
| arubanetworks | aruba_instant | >= 8.3.0 < 8.3.0.6 | 8.3.0.6 |
| arubanetworks | aruba_instant | >= 8.4.0 < 8.4.0.1 | 8.4.0.1 |
| siemens | scalance_w1750d_firmware | < 8.4.0.1 | 8.4.0.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Target vector: unauthenticated command injection via the web interface of Aruba Instant / Siemens SCALANCE W1750D; monitor for unexpected OS-level commands (copy, read, write, delete files, reboot) originating from the web management process ↗
- →Exploit requires no authentication and no user interaction (CVSS PR:N/UI:N); any HTTP request to the Aruba Instant / SCALANCE W1750D web interface from an untrusted source should be treated as suspicious and inspected for injected shell metacharacters ↗
- →Affected product scope for SCALANCE W1750D: all firmware versions prior to 8.4.0.1; use version fingerprinting on the web interface to identify unpatched devices ↗
- ·Fixed firmware versions for Aruba Instant are 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.1; detections targeting older versions should account for all four affected branches ↗
- ·No known public exploits were identified at time of advisory publication; detection rules should be tuned for low-and-slow or novel payloads rather than relying solely on known exploit signatures ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pxhj-rpvv-rcrx: A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary
ghsa_unreviewed·2022-05-24
CVE-2018-7084 [CRITICAL] CWE-78 GHSA-pxhj-rpvv-rcrx: A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary
A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary system commands within the underlying operating system. An attacker could use this ability to copy files, read configuration, write files, delete files, or reboot the device. Workaround: Block access to the Aruba Instant web interface from all untrusted users. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.1
CISA ICS
Siemens SCALANCE W1750D
cisa_ics·2019-05-14·CVSS 7.5
[HIGH] Siemens SCALANCE W1750D
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE W1750D
Last RevisedMay 14, 2019
Alert CodeICSA-19-134-07
## 1. EXECUTIVE SUMMARY
-
CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Siemens
- Equipment: SCALANCE W1750D
- Vulnerabilities: Command Injection, Information Exposure, Cross-site Scripting
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker execute arbitrary commands within the underlying operating system, discover sensitive information, take administrative actions on the device, or expose session cookies for an administ
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/108374https://cert-portal.siemens.com/productcert/pdf/ssa-549547.pdfhttps://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-001.txthttp://www.securityfocus.com/bid/108374https://cert-portal.siemens.com/productcert/pdf/ssa-549547.pdfhttps://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-001.txt
2019-05-10
Published