AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-17562

CRITICAL · CVSS 9.8 EPSS 2.92%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-05-14 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It affects Apache.

CVE
CVE-2019-17562
Severity
CRITICAL
CVSS
9.8
EPSS
2.92%
Apache

Original NVD Description

A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vulnerability is due to the lack of validation of the mac parameter in baremetal virtual router. If you insert an arbitrary shell command into the mac parameter, v-router will process the command. For example: Normal: http://{GW}:10086/baremetal/provisiondone/{mac}, Abnormal: http://{GW}:10086/baremetal/provisiondone/#';whoami;#. Mitigation of this issue is an upgrade to Apache CloudStack 4.13.1.0 or beyond.

Related CVEs

Other vulnerabilities affecting the same vendor(s)