← All CVEs

CVE-2013-6881

high · 10

CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) sector size or (2) skip count fields for the forensic imaging task.

10
CVSS
12.6%
EPSS (exploit prob.)
96th
EPSS percentile
2014-01-07
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
cru-incditto_forensic_fieldstation_firmware<= 2013jun30a
cru-incditto_forensic_fieldstationall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-6881