Overview
The Mutiny Technology virtual appliance contains a command injection vulnerability which could allow an attacker to inject commands into the appliance.
Description
CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') The Mutiny Technology virtual appliance contains a network interface menu which is vulnerable to command injection with root privileges.  | 
Impact
An authenticated attacker can run arbitrary commands on the appliance.  | 
Solution
Update  | 
Restrict access  | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | 2.1 | AV:N/AC:H/Au:S/C:N/I:P/A:N | 
| Temporal | 1.4 | E:U/RL:OF/RC:UC | 
| Environmental | 0.6 | CDP:L/TD:L/CR:ND/IR:ND/AR:ND | 
References
Acknowledgements
Thanks to Christopher Campbell for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
| CVE IDs: | CVE-2012-3001 | 
| Date Public: | 2012-10-07 | 
| Date First Published: | 2012-10-22 | 
| Date Last Updated: | 2012-10-22 12:05 UTC | 
| Document Revision: | 8 |