CVE Feed

    Dashboard / CVE / CVE-2017-9388

    CVE-2017-9388

    An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a web user interface that allows a user to manage the device. As a part of the functionality the device firmware file contains a file known as proxy.sh which allows the device to proxy a specific request to and from from another website. This is primarily used as a method of communication between the device and Vera website when the user is logged in to the https://home.getvera.com and allows the device to communicate between the device and website. One of the parameters retrieved by this specific script is "url". This parameter is not sanitized by the script correctly and is passed in a call to "eval" to execute "curl" functionality. This allows an attacker to escape from the executed command and then execute any commands of his/her choice.

    Published:Jun 17, 2019
    Last Modified:Nov 21, 2024
    EPS:Jun 17, 2019
    EPSS Score:0.01071
    CVSS Score:8.8

    Affected Products

    Vendor
    Getvera
    Product
    Veraedge
    Vendor
    Getvera
    Product
    Veraedge Firmware
    Vendor
    Getvera
    Product
    Veralite
    Vendor
    Getvera
    Product
    Veralite Firmware

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High