An OS Command Injection vulnerability in Kiloview NDI allows a low-privileged user to execute arbitrary code remotely on the device with high privileges.
This issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 .
This issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 .
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27126 | An OS Command Injection vulnerability in Kiloview NDI allows a low-privileged user to execute arbitrary code remotely on the device with high privileges. This issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 . |
Fixes
Solution
Upgrade to the firmware 2.02.0227 or later
Workaround
Restrict access to the management interface of all affected Kiloview devices by applying strict firewall rules or other available means.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2024-08-27T20:10:16.134Z
Reserved: 2024-03-04T13:18:32.464Z
Link: CVE-2024-2162
Updated: 2024-08-01T19:03:38.899Z
Status : Awaiting Analysis
Published: 2024-03-21T06:15:47.073
Modified: 2024-11-21T09:09:09.727
Link: CVE-2024-2162
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD