Impact
myVesta is vulnerable to an authenticated remote code execution flaw that allows low‑privileged users to inject arbitrary operating‑system commands through the v_ftp_user parameter when deleting FTP user accounts. The defect is identified as CWE‑78 (OS Command Injection). An attacker who can authenticate within the myVesta web interface and has permission to delete FTP accounts could craft a malicious v_ftp_user payload, causing the system to execute the supplied commands as the admin user and potentially gain full administrative control.
Affected Systems
The affected product is myVesta, identified by the CNA as myvesta:vesta. No specific version range is listed in the CNA data, so every released version of myVesta that includes the deletion functionality could be impacted. Administrators should review their deployments to confirm whether the v_ftp_user deletion path is present and whether users with low privileges can execute it.
Risk and Exploitability
The CVSS base score of 8.5 indicates a high severity. The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low current exploitation probability. However, because the flaw requires authenticated access and low‑privileged accounts that can delete FTP users are fairly common, the risk of exploitation remains non‑negligible. If an attacker succeeds, the arbitrary command execution can lead to full administrative takeover of the myVesta installation.
OpenCVE Enrichment