CVE-2010-4732
cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to execute arbitrary code…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.51%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to execute arbitrary code by using a config.html 2.conf action to replace the logo page's GIF image file with a file containing this code, a different vulnerability than CVE-2009-4463.
- CVSS 2.0
- 9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 4.51% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- intellicom/netbiter easyconnect ec150 · intellicom/netbiter modbus rtu-tcp gateway mb100 · intellicom/netbiter serial ethernet server ss100 · intellicom/netbiter webscada ws100 · intellicom/netbiter webscada ws200 · intellicom/netbiter nb100 · intellicom/netbiter nb200
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2010-10/0002.htmlExploit
- http://www.kb.cert.org/vuls/id/114560US Government Resource
- http://www.us-cert.gov/control_systems/pdf/ICSA-10-316-01A.pdfUS Government Resource
- http://archives.neohapsis.com/archives/bugtraq/2010-10/0002.htmlExploit
- http://www.kb.cert.org/vuls/id/114560US Government Resource
- http://www.us-cert.gov/control_systems/pdf/ICSA-10-316-01A.pdfUS Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.