CVE-2010-4732

UnknownEPSS 4.51%

Last modified

CVE-2010-4732 is a vulnerability of currently unknown severity. cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to execute arbitrary code by using a config.html 2.conf action to replace the logo page's GIF image file with a file containing this code, a different vulnerability than CVE-2009-4463.. EPSS estimates a 4.51% chance of exploitation in the next 30 days.

Description

cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to execute arbitrary code by using a config.html 2.conf action to replace the logo page's GIF image file with a file containing this code, a different vulnerability than CVE-2009-4463.

Metrics

EPSS Probability
4.51%

90.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IntellicomNetbiter Easyconnect Ec150All versions
IntellicomNetbiter Modbus Rtu-Tcp Gateway Mb100All versions
IntellicomNetbiter Serial Ethernet Server Ss100All versions
IntellicomNetbiter Webscada Ws100All versions
IntellicomNetbiter Webscada Ws200All versions
IntellicomNetbiter Nb100All versions
IntellicomNetbiter Nb200All versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2010-4732?
cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to execute arbitrary code by using a config.html 2.conf action to replace the logo page's GIF image file with a file containing this code, a different vulnerability than CVE-2009-4463.
How severe is CVE-2010-4732?
Severity scoring for CVE-2010-4732 is pending analysis. The EPSS model estimates a 4.51% probability of exploitation in the next 30 days.
How do I fix CVE-2010-4732?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2010-4732?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST