Impact
myVesta contains an authenticated remote code execution flaw that allows users with low privileges to inject arbitrary commands by supplying specially crafted values to the v_ftp_user parameter during the deletion of FTP users., identified as CWE-78. No specific version range is listed, so all deployments of myVesta are potentially impacted unless a later release contains a fix.
Affected Systems
The product affected by this vulnerability is myVesta vesta, as identified by the CNA. Because no specific version range is provided, every release of this product is potentially impacted. The flaw is accessed through the myVesta web interface and requires authenticated access with low privileges, typically an FTP account that can delete users. Admin or privileged users are at risk of command execution and potential takeover of the management interface.
Risk and Exploitability
The CVSS base score is 8.5, indicating a high severity. The EPSS score is less than 1%, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires authenticated access. A low‑privileged account that can delete FTP users may be leveraged to inject malicious commands, leading to full administrative takeover.
OpenCVE Enrichment