H3C.Devices.setLanguage.Command.Injection
Description
This indicates an attack attempt to exploit a Command Injection vulnerability in H3C devices.
The vulnerability is due to insufficient validation of user-supplied input in the application. A remote attacker can exploit this with a crafted request to execute arbitrary commands within the context of the system.
Affected Products
H3C Magic NX30 Pro V100R014 and earlier versions
H3C Magic NX400 V100R014 and earlier versions
H3C Magic NX15 V100R014 and earlier versions
H3C Magic R3010 V100R014 and earlier versions
H3C Magic BE18000 V100R014 and earlier versions
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Currently we are unaware of any vendor supplied patch or updates available for this issue.
Coverage
| IPS (Regular DB) | |
| IPS (Extended DB) |