CVE-2022-31794

CRITICAL

Fujitsu ETERNUS CentricStor CS8000 < 8.1 - Unauthenticated OS Command Injection

Title source: llm
STIX 2.1

Description

An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the requestTempFile function in hw_view.php. An attacker is able to influence the unitName POST parameter and inject special characters such as semicolons, backticks, or command-substitution sequences in order to force the application to execute arbitrary commands.

Scores

CVSS v3 9.8
EPSS 0.0276
EPSS Percentile 84.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (2)
fujitsu/eternus_cs8000_firmware 8.1
fujitsu/eternus_cs8000_firmware < 8.1
Published Jun 20, 2022
Tracked Since Feb 18, 2026