FTP: VanDyke VShell Server Trigger Command Injection

This signature detects attempts to exploit a known vulnerability against VanDyke VShell Server. A successful attack can lead to command injection and arbitrary code execution

Extended Description

Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value.

References

CVE: CVE-2022-28054

Short Name
FTP:USER:VANDYKE-VSHELL-CMD-INJ
Severity
Major
Recommended
False
Recommended Action
Drop
Category
FTP
Keywords
CVE-2022-28054 Command Injection Server Trigger VShell VanDyke
Release Date
07/14/2022
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3509
False Positive
Unknown

Found a potential security threat?