CVE-2019-15020

CRITICAL

Zingbox Inspector < 1.293 - Command Injection via Invalid Software Update Image

Title source: llm
STIX 2.1

Description

A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector that could result in command injection.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://security.paloaltonetworks.com/CVE-2019-15020

Scores

CVSS v3 9.8
EPSS 0.0089
EPSS Percentile 54.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-346
Status published
Products (1)
zingbox/inspector < 1.293
Published Oct 09, 2019
Tracked Since Feb 18, 2026