CVE-2013-6881

CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) sector size or (2) skip count fields for the forensic imaging task.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:cru-inc:ditto_forensic_fieldstation_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:cru-inc:ditto_forensic_fieldstation:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2014-01-07 17:04

Updated : 2024-02-04 18:16


NVD link : CVE-2013-6881

Mitre link : CVE-2013-6881

CVE.ORG link : CVE-2013-6881


JSON object : View

Products Affected

cru-inc

  • ditto_forensic_fieldstation_firmware
  • ditto_forensic_fieldstation
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')