Description 锐捷统一上网行为管理与审计系统RG-UAC 20240428及之前版本中存在命令注入漏洞,此漏洞是由于未充分验证用户输入ip_addr_add_commit.php的数据所导致的。
References https://cve.imfht.com/detail/CVE-2024-4505 https://cve.imfht.com/product/RG-UAC https://nvd.nist.gov/vuln/detail/cve-2024-4505 https://www.cve.org/CVERecord?id=CVE-2024-4505 https://access.redhat.com/security/cve/cve-2024-4505 https://cvefeed.io/vuln/product/143152/ruijierg-uac_6000-e50/?page=1 https://feedly.com/cve/vendors/ruijie https://vuldb.com/es/?id.263109 https://vuldb.com/?id.263109 https://vulners.com/search/vendors/ruijie/products/rg-uac%206000-e50c%20firmware
Related Vulnerabilities锐捷RG-UAC static_convert.php 远程命令执行漏洞锐捷RG-UAC 6000-ISG-php-存在命令执行漏洞锐捷RG-UAC CVE-2024-6269 命令注入漏洞锐捷RG-UAC online_check.php 远程命令执行漏洞锐捷RG-UAC nmc_sync.php 命令执行锐捷RG-UAC统一上网行为管理审计系统账号密码信息泄露漏洞