IM
IronMonkey Threat Research

CVE-2025-50123 HIGH

Published: 2025-07-11 | Last Modified: 2026-04-15 | Status: Deferred

Description

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote command execution by a privileged account when the server is accessed via a console and through exploitation of the hostname input.

Additional Descriptions (1)

Existe una vulnerabilidad CWE-94: Control inadecuado de la generación de código ('Inyección de código') que podría provocar la ejecución remota de comandos por parte de una cuenta privilegiada cuando se accede al servidor mediante una consola y mediante la explotación de la entrada del nombre de host.

CVSS Metrics

Base Score: 7.2 (HIGH)

CVSS:4.0/AV:P/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack VectorPHYSICAL
Attack ComplexityLOW
Attack RequirementsPRESENT
Privileges RequiredHIGH
User InteractionNONE
Vulnerability ConfidentialityHIGH
Vulnerability IntegrityHIGH
Vulnerability AvailabilityHIGH
Subsequent ConfidentialityHIGH
Subsequent IntegrityLOW
Subsequent AvailabilityHIGH

Source: [email protected]

Type: Secondary

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-94
Notification
Message here