Vulnerabilities
Vulnerable Software
The novish command-line interface, included in NoviFlow NoviWare before NW500.2.12 and deployed on NoviSwitch devices, is vulnerable to command injection in the "show status destination ipaddr" command. This could be used by a read-only user (monitoring group) or admin to execute commands on the operating system.
CVSS Score
8.8
EPSS Score
0.075
Published
2020-08-17


Contact Us

Shodan ® - All rights reserved