Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
This Cyber News was published on www.tenable.com. Publication date: Tue, 05 Dec 2023 00:00:00 +0000