EndRun Technologies Sonoma D12 Network Time Server OS Command Injection Vulnerability
Vulnerability
A command injection vulnerability allowing unauthorized remote code execution has been identified in the EndRun Technologies Sonoma D12 Network Time Server (GPS) firmware version 6010-0071-000 v4.00. This vulnerability arises from improper handling of user input, which could be exploited to execute arbitrary commands on the server.
Impact
Exploitation of this vulnerability could lead to unauthorized remote code execution, privilege escalation, and full system compromise, requiring elevated privileges.
Remediation
The vendor has provided interim mitigation steps, which include disabling web-management access. These steps have been verified as effective by the vendor, but should be evaluated for operational impact before applying in production environments.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
