TeamViewer DEX Command Injection Vulnerability in 1E-Explorer-TachyonCore-CheckSimpleIoC Instruction
Vulnerability
A command injection vulnerability exists in TeamViewer DEX (formerly 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction. This vulnerability arises from improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation of this vulnerability enables remote execution of elevated commands on devices connected to the platform.
Impact
Exploitation allows for remote execution of elevated commands on affected devices.
Remediation
Users should delete the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction from the platform. For TeamViewer DEX On-Premise customers, contact your Customer Success Manager for assistance.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
