CVE Database
/

CVE-2017-12785

Back to search

CVE-2017-12785

Published: Aug 22, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, is prone to a buffer overflow in the "show log cli" command. This could be used by a read-only user (monitor role) to gain privileged (root) code execution on the switch via command injection.

VendorProductVersions

n/a

n/a

affected
n/a

References

42518
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now