RULE(RULE ID:332291)

Rule General Information
Release Date: 2021-01-21
Rule Name: rConfig search.crud.php Command Injection Vulnerability (CVE-2019-16663)
Severity:
CVE ID:
Rule Protection Details
Description: A command injection vulnerability has been reported in rConfig Network Device Configuration Tool. The vulnerability is due to insufficient input validation in the search.crud.php. A remote, authenticated attacker can exploit this vulnerability by sending a crafted request to the target server. Successful exploitation could result in arbitrary command execution with the web server privilege on the target system.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://drive.google.com/open?id=1XmR2MSMb3cKARFk3XxmPkwz6GhAP1JxL
https://drive.google.com/open?id=1kQGmboKfwob4RwlMjnv6ER2Za1GUptOi
https://gist.github.com/mhaskar/e7e454c7cb0dd9a139b0a43691e258a0
https://rconfig.com/download
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://rconfig.com