VYPR
High severity8.6NVD Advisory· Published Jun 3, 2019· Updated Jun 2, 2026

CVE-2017-14853

CVE-2017-14853

Description

Orpak SiteOmat OrCU component, prior to 2017-09-25, allows code injection via a search query that directly executes shell commands, enabling remote unauthenticated attackers to run arbitrary commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Orpak SiteOmat OrCU component, prior to 2017-09-25, allows code injection via a search query that directly executes shell commands, enabling remote unauthenticated attackers to run arbitrary commands.

Vulnerability

Code injection vulnerability (CWE-77) exists in the Orpak SiteOmat OrCU component in all versions prior to 2017-09-25. The bug is triggered by a search query that passes unsanitized user input directly to a shell command without proper neutralization. Affected products: SiteOmat versions prior to 6.4.414.122 [1].

Exploitation

An attacker can exploit this vulnerability remotely over the network without authentication [1]. By tampering with the request parameters, the attacker injects arbitrary shell commands into the search query, which then execute on the underlying operating system. The resulting command output is returned in the application response. The low skill level required for exploitation and the fact that public exploits are available make this easily accessible [1].

Impact

Successful exploitation allows an attacker to execute arbitrary shell commands on the device with the privileges of the application process. This leads to arbitrary remote code execution, which could result in denial-of-service conditions and unauthorized access to view and edit monitoring, configuration, and payment information. The overall impact on confidentiality, integrity, and availability is high [1].

Mitigation

The vendor, Orpak (acquired by Gilbarco Veeder-Root), released a fix in SiteOmat version 6.4.414.122 [1]. Users should upgrade to this version or later. As of the advisory date (2019-06-03), no workaround was provided; timely patching is recommended. This CVE is not listed on the CISA KEV catalog [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Orpak/Orpak SiteOmat OrCUdescription
  • Orpak/SiteOmatllm-fuzzy
    Range: <2017-09-25

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

3

News mentions

0

No linked articles in our index yet.