An OS command injection
vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an
authenticated attacker to achieve remote code execution on the system by
sending malicious input injected into the server username field of the
import preconfiguration action in the API V1 route.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 6
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Copeland Xweb_300d_Pro_Firmware
cpe:2.3:o:copeland:xweb_300d_pro_firmware:*:*:*:*:*:*:*:*
|
— |
<= 1.12.1
|
|
Copeland Xweb_300d_Pro
cpe:2.3:h:copeland:xweb_300d_pro:-:*:*:*:*:*:*:*
|
— | — |
|
Copeland Xweb_500d_Pro_Firmware
cpe:2.3:o:copeland:xweb_500d_pro_firmware:*:*:*:*:*:*:*:*
|
— |
<= 1.12.1
|
|
Copeland Xweb_500d_Pro
cpe:2.3:h:copeland:xweb_500d_pro:-:*:*:*:*:*:*:*
|
— | — |
|
Copeland Xweb_500b_Pro_Firmware
cpe:2.3:o:copeland:xweb_500b_pro_firmware:*:*:*:*:*:*:*:*
|
— |
<= 1.12.1
|
|
Copeland Xweb_500b_Pro
cpe:2.3:h:copeland:xweb_500b_pro:-:*:*:*:*:*:*:*
|
— | — |