Twenty Year Anniversary

Mutiny Monitoring Appliance Command Injection

Mutiny Monitoring Appliance Command Injection
Posted Aug 23, 2018
Authored by Reginald Dodd

Mutiny Monitoring Appliance versions prior to 6.1.0-5263 suffer from a command injection vulnerability.

tags | advisory
advisories | CVE-2018-15529
MD5 | 36b0e15c2971215ade2fa674c7a64173

Mutiny Monitoring Appliance Command Injection

Change Mirror Download
[Title]
Mutiny Monitoring Appliance < 6.1.0-5263 - Command Injection (CVE-2018-15529)

[Product]
Mutiny Monitoring Appliance
https://www.mutiny.com/

[CVE]
CVE-2018-15529

[Credit]
Reginald Dodd

[Description]
A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to the admin interface, to inject arbitrary commands within the filename of a system upgrade upload.

[Version Tested]
Version 6.1.0-5191 was tested and is vulnerable.

[Solution]
Upgrade to v6.1.0-5263.

[Reference]
https://www.mutiny.com/mutiny-support/previous-releases/ (Under the "Patches/Bugs" Fixed section)

[Timeline]
August 12, 2018 - A detailed report and exploit was sent to the vendor.
August 13, 2018 - The vendor released a patch (version 6.1.0-5263).
August 19, 2018 - Mitre assigned a CVE.

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

October 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    26 Files
  • 2
    Oct 2nd
    15 Files
  • 3
    Oct 3rd
    15 Files
  • 4
    Oct 4th
    15 Files
  • 5
    Oct 5th
    15 Files
  • 6
    Oct 6th
    2 Files
  • 7
    Oct 7th
    3 Files
  • 8
    Oct 8th
    23 Files
  • 9
    Oct 9th
    16 Files
  • 10
    Oct 10th
    15 Files
  • 11
    Oct 11th
    19 Files
  • 12
    Oct 12th
    16 Files
  • 13
    Oct 13th
    2 Files
  • 14
    Oct 14th
    2 Files
  • 15
    Oct 15th
    15 Files
  • 16
    Oct 16th
    0 Files
  • 17
    Oct 17th
    0 Files
  • 18
    Oct 18th
    0 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close