Description
An OS Command Injection vulnerability in Kiloview NDI allows a low-privileged user to execute arbitrary code remotely on the device with high privileges.
This issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 .
This issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 .
No analysis available yet.
Remediation
Vendor Solution
Upgrade to the firmware 2.02.0227 or later
Vendor Workaround
Restrict access to the management interface of all affected Kiloview devices by applying strict firewall rules or other available means.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27126 | An OS Command Injection vulnerability in Kiloview NDI allows a low-privileged user to execute arbitrary code remotely on the device with high privileges. This issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 . |
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2024-08-27T20:10:16.134Z
Reserved: 2024-03-04T13:18:32.464Z
Link: CVE-2024-2162
Updated: 2024-08-01T19:03:38.899Z
Status : Awaiting Analysis
Published: 2024-03-21T06:15:47.073
Modified: 2024-11-21T09:09:09.727
Link: CVE-2024-2162
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD