CVE-2019-12585

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
03/06/2019
Last modified:
24/08/2020

Description

Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apcupsd:apcupsd:0.3.91_5:*:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:*:*:*:*:*:*:*:* 2.4.4 (excluding)
cpe:2.3:a:netgate:pfsense:2.4.4:-:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:2.4.4:p1:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:2.4.4:p2:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:2.4.4:p3:*:*:*:*:*:*