CVE-2013-6881
UnknownEPSS 12.61%
Last modified
CVE-2013-6881 is a vulnerability of currently unknown severity. CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) sector size or (2) skip count fields for the forensic imaging task.. EPSS estimates a 12.61% chance of exploitation in the next 30 days.
Description
CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) sector size or (2) skip count fields for the forensic imaging task.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cru-Inc | Ditto Forensic Fieldstation Firmware | <= 2013jun30a |
| Cru-Inc | Ditto Forensic Fieldstation | All versions |
References
- http://secunia.com/advisories/55989Vendor Advisory
- http://secunia.com/advisories/55989Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-6881?
CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) sector size or (2) skip count fields for the forensic imaging task.
How severe is CVE-2013-6881?
Severity scoring for CVE-2013-6881 is pending analysis. The EPSS model estimates a 12.61% probability of exploitation in the next 30 days.
How do I fix CVE-2013-6881?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-6875SQL injection vulnerability in functions/prepend_adm.php in …
- CVE-2013-6876The (1) pty_init_terminal and (2) pipe_init_terminal functio…
- CVE-2013-6877Heap-based buffer overflow in RealNetworks RealPlayer before…
- CVE-2013-6878Cross-site scripting (XSS) vulnerability in the Mijosoft Mij…6.1
- CVE-2013-6879The Mijosoft MijoSearch component 2.0.1 and earlier for Joom…5.3
- CVE-2013-6880Open redirect in proxy.php in FlashCanvas before 1.6 allows …6.1
- CVE-2013-6882Multiple cross-site scripting (XSS) vulnerabilities in CRU D…
- CVE-2013-6883Cross-site request forgery (CSRF) vulnerability in CRU Ditto…
- CVE-2013-6884The write-blocker in CRU Ditto Forensic FieldStation with fi…
- CVE-2013-6885The microcode on AMD 16h 00h through 0Fh processors does not…
- CVE-2013-6886RealVNC VNC 5.0.6 on Mac OS X, Linux, and UNIX allows local …
- CVE-2013-6887OpenJPEG 1.5.1 allows remote attackers to cause a denial of …
Are you affected by CVE-2013-6881?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
