Arbitrary Command Execution in IBM GCM16 and GCM32 Global Console Manager Switches

Arbitrary Command Execution in IBM GCM16 and GCM32 Global Console Manager Switches

CVE-2014-3085 · HIGH Severity

AV:N/AC:H/AU:S/C:C/I:C/A:C

systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the lpres parameter.

Learn more about our Cis Benchmark Audit For Ibm I.