Impact
A vulnerability was identified in Sangfor Operation and Maintenance Management System up to version 3.0.12. The affected component is the SessionController function within the SSH Protocol Handler. By manipulating the keypassword argument, an attacker can inject arbitrary operating‑system commands that are executed with the privileges of the running service. The flaw allows remote execution, and a publicly available proof‑of‑concept exploit can be used.
Affected Systems
All instances of Sangfor Operation and Maintenance Management System version 3.0.12 or earlier are vulnerable. The impacted component is the SSH Protocol Handler located in the /isomp-protocol/protocol/session file. Organizations using this product must verify whether they are running a vulnerable release and take remediation measures accordingly.
Risk and Exploitability
The CVSS score of 8.7 reflects high severity, with the exploit being achievable remotely. EPSS indicates a 6% likelihood of exploitation, and the vulnerability is not yet in the CISA KEV catalog. The publicly available proof‑of‑concept demonstrates that the attack can be launched over the network by manipulating the keypassword argument, although the CVE does not specify whether authentication is required.
OpenCVE Enrichment