Cradlepoint IBR600 Command Injection
Published Nov 29, 2022
7.6
HIGHCVSS 3.1
EPSS 0.32%
Description
Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers with non-superuser credentials to gain full, unrestrictive shell access which may allow an attacker to execute arbitrary code.
Affected products
-
- Version 0StatusaffectedConstraints<=6.5.0.160bc2e
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Cradlepoint | IBR600 | unaffected |
|
Configuration 1
- 1.1
Running on/with
- n/a
Configuration 2
- 1.1
Running on/with
- n/a
Configuration 3
- 1.1
Running on/with
- n/a
Configuration 4
- 1.1
Running on/with
- n/a
Configuration 5
- 1.1
Running on/with
- n/a
Configuration 6
- 1.1
Running on/with
- n/a
Configuration 7
- ≥ 1.0 · ≤ 1.2
Running on/with
- n/a
Configuration 8
- ≥ 1.0 · ≤ 1.2
Running on/with
- n/a
Configuration 9
- ≥ 1.0 · ≤ 1.2
Running on/with
- n/a
Configuration 10
- 2.2
Running on/with
- n/a
Configuration 11
- 2.2
Running on/with
- n/a
Configuration 12
- 2.2
Running on/with
- n/a
Configuration 13
- 2.2
Running on/with
- n/a
Configuration 14
- ≥ 1.0 · ≤ 2.4
Running on/with
- n/a
Configuration 15
- ≥ 1.0 · ≤ 2.4
Running on/with
- n/a
Configuration 16
- ≥ 1.0 · ≤ 2.4
Running on/with
- n/a
Configuration 17
- ≥ 1.0 · ≤ 2.4
Running on/with
- n/a
Configuration 18
- ≥ 1.0 · ≤ 2.4
Running on/with
- n/a
Configuration 19
- 1.0
- 1.1
Running on/with
- n/a
Configuration 20
- 1.2
- 1.3
Running on/with
- n/a
Configuration 21
- 1.2
- 1.3
Running on/with
- n/a
Configuration 22
- 1.2
- 1.3
Running on/with
- n/a
Configuration 23
- 1.2
- 1.3
Running on/with
- n/a
Configuration 24
- 1.2
Running on/with
- n/a
Configuration 25
- 1.2
Running on/with
- n/a
Configuration 26
- 1.2
Running on/with
- n/a
Configuration 27
- 1.2
Running on/with
- n/a
Configuration 28
- 1.2
Running on/with
- n/a
Configuration 29
- 1.2
Running on/with
- n/a
Configuration 30
- 1.2
Running on/with
- n/a
Configuration 31
- 1.2
Running on/with
- n/a
Configuration 32
- ≥ 1.2 · ≤ 2.0
Running on/with
- n/a
Configuration 33
- ≥ 1.2 · ≤ 2.0
Running on/with
- n/a
Configuration 34
- ≥ 1.2 · ≤ 2.0
Running on/with
- n/a
Configuration 35
- ≥ 1.2 · ≤ 2.0
Running on/with
- n/a
Configuration 36
- ≥ 1.2 · ≤ 2.0
Running on/with
- n/a
Configuration 37
- ≥ 1.2 · ≤ 2.0
Running on/with
- n/a
Configuration 38
- ≥ 1.2 · ≤ 2.0
Running on/with
- n/a
Configuration 39
- ≥ 1.2 · ≤ 2.0
Running on/with
- n/a
Configuration 40
- ≥ 1.2 · ≤ 2.0
Running on/with
- n/a
Configuration 41
- ≥ 1.2 · ≤ 2.0
Running on/with
- n/a
Configuration 42
- ≥ 1.2 · ≤ 2.0
Running on/with
- n/a
Configuration 43
- ≥ 1.2 · ≤ 2.0
Running on/with
- n/a
Configuration 44
- ≥ 1.3 · ≤ 1.5
Running on/with
- n/a
Configuration 45
- ≥ 1.3 · ≤ 1.5
Running on/with
- n/a
Configuration 46
- ≥ 1.3 · ≤ 1.5
Running on/with
- n/a
Configuration 47
- ≥ 1.3 · ≤ 1.5
Running on/with
- n/a
Configuration 48
- ≥ 1.3 · ≤ 1.5
Running on/with
- n/a
Configuration 49
- ≥ 1.3 · ≤ 1.5
Running on/with
- n/a
Configuration 50
- ≥ 1.3 · ≤ 1.5
Running on/with
- n/a
Configuration 51
- ≥ 1.3 · ≤ 1.5
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Cradlepoint recommends users to update to at least version:
* NCOS v7.22.70
NCOS release 7.1.0 and greater are no longer available for manual or offline download and are performed via the NetCloud Manager, which requires a subscription. For more information and NCOS upgrade best practices visit Cradlepoint Netcloud Service https://cradlepoint.com/products/netcloud-service/ .
For more information about the latest update, see the Cradlepoint Release Notes https://d2c9o94y5j661e.cloudfront.net/FW-ReleaseNotesNCOS7.22.70-050722.pdf .
References (2)
Change history (0)
No recorded changes yet.