← All CVEs

CVE-2017-6048

high · 8.8

A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataLogger V5.37c-1.43c and prior, SenNet Solar Datalogger V5.03-1.56a and prior, and SenNet Multitask Meter V5.21a-1.18b and prior. Successful exploitation of this vulnerability could result in the attacker breaking out of the jailed shell and gaining full access to the system.

8.8
CVSS
15.5%
EPSS (exploit prob.)
97th
EPSS percentile
2017-05-19
Published

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-77

Affected products

VendorProductAffected versions
satel-iberiasennet_multitask_meter<= 5.21a-1.18b
satel-iberiasennet_optimal_datalogger<= 5.37c-1.43c
satel-iberiasennet_solar_datalogger<= 5.03-1.56a

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-6048