An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. It stores SMS messages in .NET serialized format on the filesystem. By generating (and writing to the disk) malicious .NET serialized files, an attacker can trick the product into deserializing them, resulting in arbitrary code execution.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-09-29T13:08:12
Updated: 2024-08-04T12:32:14.691Z
Reserved: 2020-06-11T00:00:00
Link: CVE-2020-14030
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-09-30T18:15:21.537
Modified: 2024-11-21T05:02:23.393
Link: CVE-2020-14030
Redhat
No data.