CVE-2017-14853: Orpak Siteomat

High severity, CVSS 8.6. EPSS: 3.8% chance of exploitation in the next 30 days.

The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search query that uses a direct shell command. By tampering with the request, an attacker is able to run shell commands and receive valid output from the device.

Affected products

  • Orpak Siteomat: before 6.4.414.122 (fixed in 6.4.414.122)

Published 2019-06-03. Last modified 2026-06-17.