An OS Command Injection vulnerability in Kiloview NDI allows a low-privileged user to execute arbitrary code remotely on the device with high privileges. This issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 .
Solution:
Workaround:
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
https://www.kiloview.com/en/support/download/n3-for-ndi/ | release notes |
https://www.kiloview.com/en/support/download/n3-s-firmware-download/ | release notes |
https://www.kiloview.com/en/support/download/1779/ | release notes |
https://www.kiloview.com/en/support/download/n20-firmware-download/ | release notes |
https://www.kiloview.com/en/support/download/n30-for-ndi/ | release notes |
https://www.kiloview.com/en/support/download/n40/ | release notes |