CVE-2016-1608 is a critical command injection vulnerability affecting Novell Filr versions prior to 1.2 Security Update 3 and 2.0 Security Update 2. Authenticated remote attackers can execute arbitrary commands by injecting shell metacharacters into the ntpServer parameter within the vaconfig/time function. This vulnerability carries a high CVSS score of 8.8, indicating a severe impact with complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, public exploit code exists on ExploitDB, and it has garnered media attention and community discussion, suggesting a potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.2CPE matchmatch criteria | cpe:2.3:a:novell:filr:*:security_update_2:*:*:*:*:*:* | ||
<= 2.0CPE matchmatch criteria | cpe:2.3:a:novell:filr:*:security_update_1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.