Executive brief
Electerm, an open-source terminal and file transfer client, contains a vulnerability that allows unauthorized users to execute commands on the host system. This could lead to a complete takeover of the computer where the application is installed, potentially exposing sensitive files and corporate data. The issue stems from the application's service accepting unverified requests from the network.
Technical details
Electerm version 1.3.22 and earlier is vulnerable to OS command injection (CWE-78) and missing authentication for critical functions (CWE-306). The vulnerability exists because the electerm service processes unverified network requests without proper neutralization of special elements used in OS commands. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to the service, resulting in arbitrary code execution with the privileges of the application. As of the advisory publication, no patched version has been identified in the source material.
Affected products
- electerm electerm <= 1.3.22
Timeline
- 2023-01-20: disclosed: NVD publication date
- 2023-01-20: advisory: GitHub Advisory published