Command Execution Vulnerability in INN Daemon by ISC
CVE-1999-0043
9.8CRITICAL
What is CVE-1999-0043?
The INN daemon (innd) version 1.5 is vulnerable to command execution due to improper handling of shell metacharacters within control messages such as 'newgroup' and 'rmgroup'. An attacker can exploit this vulnerability to execute arbitrary commands on the server, posing a significant security risk to affected installations. Proper input validation and sanitization measures should be implemented to mitigate this issue.
References
EPSS Score
44% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability Reserved
Vulnerability published