Is Reporter vulnerable to Nginx Remote Code Execution (RCE) and Arbitrary Code Execution Vulnerability
search cancel

Is Reporter vulnerable to Nginx Remote Code Execution (RCE) and Arbitrary Code Execution Vulnerability

book

Article ID: 254345

calendar_today

Updated On:

Products

Reporter Reporter-S500 Reporter-VA

Issue/Introduction

The vulnerability assessment tool may generate an alert as below for Reporter device's port 8082.

1) CVE-2021-23017 - Nginx Arbitrary Code Execution Vulnerability

2) Nginx Remote Code Execution (RCE) Vulnerability (Zero Day)

 

Environment

Reporter v11.x

Cause

Vulnerability assessment software detects these vulnerabilities based on the Ngnix version (nginx/1.18.0) and not by performing the actual exploitation.

Resolution

Reporter is a hardcoded special-purpose operating system.
It's not possible to install or run any arbitrary code on it and the Reporter v11.x device is allowed to respond on port 8082 via the Management Center's specially crafted API requests only.

The product has been reviewed and determined not to be vulnerable.