CVE-2019-12491

OnApp before 5.0.0-88, 5.5.0-93, and 6.0.0-196 allows an attacker to run arbitrary commands with root privileges on servers managed by OnApp for XEN/KVM hypervisors. To exploit the vulnerability an attacker has to have control of a single server on a given cloud (e.g. by renting one). From the source server, the attacker can craft any command and trigger the OnApp platform to execute that command with root privileges on a target server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.6 MEDIUM
NETWORK
HIGH
HIGH
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
VendorProductVersion
onapponapp
5.0.0
onapponapp
5.0.0:update_79
onapponapp
5.0.0:update_82
onapponapp
5.0.0:update_83
onapponapp
5.0.0:update_87
onapponapp
5.1.0
onapponapp
5.1.0:update_16
onapponapp
5.2.0
onapponapp
5.3.0
onapponapp
5.3.0:update_41
onapponapp
5.4.0
onapponapp
5.4.0:update_66
onapponapp
5.4.0:update_70
onapponapp
5.4.0:update_72
onapponapp
5.4.0:update_76
onapponapp
5.4.0:update_82
onapponapp
5.4.0:update_84
onapponapp
5.5.0
onapponapp
5.5.0:update_50
onapponapp
5.5.0:update_59
onapponapp
5.5.0:update_65
onapponapp
5.5.0:update_75
onapponapp
5.5.0:update_80
onapponapp
5.5.0:update_83
onapponapp
5.5.0:update_87
onapponapp
5.5.0:update_90
onapponapp
5.5.0:update_92
onapponapp
5.6.0
onapponapp
5.6.0:update_83
onapponapp
5.7.0
onapponapp
5.8.0
onapponapp
5.9.0
onapponapp
5.10.0
onapponapp
6.0:update_122
onapponapp
6.0:update_152
onapponapp
6.0:update_159
onapponapp
6.0:update_62
onapponapp
6.0:update_80
onapponapp
6.0:update_98
onapponapp
6.0.0
𝑥
= Vulnerable software versions