A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is compromised. Affected Products: SpaceLogic C-Bus Home Controller (5200WHC2), formerly known as C-Bus Wiser Homer Controller MK2 (V1.31.460 and prior)
Una CWE-78: Se presenta una vulnerabilidad de Neutralización Inapropiada de Elementos Especiales usados en un Comando del Sistema Operativo ("Inyección de comandos del SO") que podría causar una explotación remota de root cuando el comando está comprometido. Productos afectados: SpaceLogic C-Bus Home Controller (5200WHC2), anteriormente conocido como C-Bus Wiser Homer Controller MK2 (versiones V1.31.460 y anteriores)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-78
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| schneider-electric | spacelogic_c-bus_home_controller_firmware | * | <built-in method update of dict object at 0x7e613410bd40> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:spacelogic_c-bus_home_controller_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:spacelogic_c-bus_home_controller:-:*:*:*:*:*:*:* |