CVE Feed

    Dashboard / CVE / CVE-2018-4031

    CVE-2018-4031

    An exploitable vulnerability exists in the safe browsing function of the CUJO Smart Firewall, version 7003. The flaw lies in the way the safe browsing function parses HTTP requests. The server hostname is extracted from captured HTTP/HTTPS requests and inserted as part of a Lua statement without prior sanitization, which results in arbitrary Lua script execution in the kernel. An attacker could send an HTTP request to exploit this vulnerability.

    Published:Oct 31, 2019
    Last Modified:Nov 21, 2024
    EPS:Oct 31, 2019
    EPSS Score:0.0041
    CVSS Score:10

    Affected Products

    Vendor
    Getcujo
    Product
    Smart Firewall

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High