VendorsRiello-upsnetman_204any version
Vulnerabilities

Riello-ups Riello Elletronica NetMan 204 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2017-6900
An issue was discovered in Riello NetMan 204 14-2 and 15-2. The issue is with the login script and wrongpass Python script used for authentication. When calling wrongpass, the variables $VAL0 and $VAL1 should be enclosed in quotes to prevent the potential for Bash command injection. Further to this, VAL0 and VAL1 should be sanitised to ensure they do not contain malicious characters. Passing it the username of '-' will cause it to time out and log the user in because of poor error handling. This will log the attacker in as an administrator where the telnet / ssh services can be enabled, and the credentials for local users can be reset. Also, login.cgi accepts the username as a GET parameter, so login can be achieved by browsing to the /cgi-bin/login.cgi?username=-%20a URI.
Published 2019-07-03 · Modified
10.0EPSS 0.026
CVE-2024-8878
Unauthenticated Password Reset
Published 2024-09-24 · Modified
10.0EPSS 0.013
CVE-2022-47893
NetMan 204 Remote Code Execution
Published 2023-10-03 · Modified
10.0EPSS 0.012
CVE-2024-8877
SQL Injection
Published 2024-09-24 · Modified
9.8EPSS 0.773
CVE-2022-47891
Admin password reset in NetMan 204
Published 2023-10-03 · Modified
8.8EPSS 0.006
CVE-2022-3372
Cross-Site Request Forgery (CSRF) in Riello UPS Netman-204
Published 2023-06-21 · Modified
8.8EPSS 0.004
CVE-2022-47892
Information disclosure in NetMan 204
Published 2023-10-03 · Modified
7.5EPSS 0.005