Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-3267

Опубликовано: 14 авг. 2023
Источник: nvd
CVSS3: 9.1
CVSS3: 8.8
EPSS Низкий

Описание

When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An authenticated attacker can leverage this vulnerability to execute arbitrary code with system-level access to the CyberPower PowerPanel Enterprise server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cyberpower:powerpanel_server:*:*:*:*:enterprise:*:*:*
Версия до 2.6.9 (исключая)

EPSS

Процентиль: 46%
0.00232
Низкий

9.1 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-78
CWE-78

Связанные уязвимости

CVSS3: 9.1
github
больше 2 лет назад

When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An authenticated attacker can leverage this vulnerability to execute arbitrary code with system-level access to the CyberPower PowerPanel Enterprise server.

EPSS

Процентиль: 46%
0.00232
Низкий

9.1 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-78
CWE-78