Ilevia EVE X1 Server Authenticated OS Command Injection Vulnerability
Vulnerability
Authenticated OS command injection vulnerabilities have been identified in Ilevia EVE X1 Server firmware versions through 4.7.18.0.eden. These vulnerabilities exist in multiple web-accessible PHP scripts that utilize the exec() function, allowing authenticated attackers to execute arbitrary commands on the server. Ilevia has chosen not to address this vulnerability and advises customers to avoid exposing port 8080 to the internet.
Impact
Exploitation of this vulnerability allows authenticated users to inject and execute arbitrary operating system commands on the server where the EVE X1 Server is running.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
