Aerohive.NetConfig.UI.log.Remote.Code.Execution
Description
This indicates an attack attempt to exploit a Command Injection vulnerability in the Extreme Network Aerohive NetConfig UI.
The vulnerability is due to insufficient sanitizing when vulnerable system handle an crafted HTTP request. A remote attacker may be able to exploit this to execute arbitrary code within the context of the application.
Affected Products
Aerohive NetConfig prior to version 10.0r8a
Impact
System Compromise: Remote attackers can execute arbitrary code in the context of the affected application.
Recommended Actions
Currently we are not aware of any vendor supplied patch for this issue
Coverage
| IPS (Regular DB) | |
| IPS (Extended DB) |