LANDesk.Gateway.Web.Interface.Command.Injection

description-logoDescription

This indicates an attack attempt to exploit a Cross Site Request Forgery vulnerability in LANDesk Management Gateway.
It allows a remote attacker to execute arbitrary code via sending a crafted web page.

affected-products-logoAffected Products

LANDesk Management Gateway 4.0 GSBWEB version 1.61s
LANDesk Management Gateway 4.2 GSBWEB version 1.61

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Currently we are not aware of any vendor supplied patch for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2021-01-11 16.995
2019-02-01 14.540 Name:Landesk.
Gateway.
Web.
Interface.
Command.
Injection:LANDesk.
Gateway.
Web.
Interface.
Command.
Injection