Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-43488

Опубликовано: 25 окт. 2023
Источник: nvd
CVSS3: 7.9
CVSS3: 7.8
EPSS Низкий

Описание

The vulnerability allows a low privileged (untrusted) application to modify a critical system property that should be denied, in order to enable the ADB (Android Debug Bridge) protocol to be exposed on the network, exploiting it to gain a privileged shell on the device without requiring the physical access through USB.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:boschrexroth:ctrlx_hmi_web_panel_wr2107_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:boschrexroth:ctrlx_hmi_web_panel_wr2107:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:boschrexroth:ctrlx_hmi_web_panel_wr2110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:boschrexroth:ctrlx_hmi_web_panel_wr2110:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:o:boschrexroth:ctrlx_hmi_web_panel_wr2115_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:boschrexroth:ctrlx_hmi_web_panel_wr2115:-:*:*:*:*:*:*:*

EPSS

Процентиль: 19%
0.0006
Низкий

7.9 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-862
CWE-862

Связанные уязвимости

CVSS3: 7.9
github
больше 2 лет назад

The vulnerability allows a low privileged (untrusted) application to modify a critical system property that should be denied, in order to enable the ADB (Android Debug Bridge) protocol to be exposed on the network, exploiting it to gain a privileged shell on the device without requiring the physical access through USB.

EPSS

Процентиль: 19%
0.0006
Низкий

7.9 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-862
CWE-862