CVE-2019-1584

Description

A security vulnerability exists in Zingbox Inspector that allows for remote code execution if the Inspector were sent a malicious command from the Zingbox cloud, or if the Zingbox Inspector were tampered with to connect to an attackers cloud endpoint. (Ref: CVE-2019-1584)This vulnerability can only be triggered by malicous commands sent by the Zingbox cloud to the Zingbox Inspector software. The Zingbox Inspector is configured to connect only to an authorized Zingbox cloud, which is authenticated using PKI. The vulnerability allows for remote code execution only if the Zingbox Inspector or Zingbox cloud are tampered with in order to send malicious commands to the Zingbox Inspector software.This issue affects Zingbox Inspector, versions 1.293 and earlier.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
2.357

Associated Vulnerability

VulnerabilityOS Platform
Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability (CVE-2019-1584)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234