Vulnerabilities
Vulnerable Software
Softnas:  >> Cloud  >> 3.4.7.3  Security Vulnerabilities
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary commands with root permissions.
CVSS Score
9.8
EPSS Score
0.742
Published
2018-08-04


Contact Us

Shodan ® - All rights reserved