Check Point Reference: | CPAI-2014-1874 |
Date Published: | 14 Oct 2014 |
Severity: | Medium |
Last Updated: | Tuesday 14 October, 2014 |
Source: | mitre.org |
Industry Reference: | CVE-2012-0261 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | op5 Monitor versions 5.3.5, 5.4.0, 5.4.2, 5.5.0, 5.5.1 |
Vulnerability Description | A command execution vulnerability has been reported in op5 Monitor. The vulnerability is due to an input validation flaw related to the system-op5config component. A remote attacker can exploit this vulnerability to execute arbitrary shell commands via command injection. |
SmartView Tracker will log the following entries:
Attack Name: Web Server Enforcement Violation.
Attack Information: op5 Monitor license.php Remote Command Execution