Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-49695

Опубликовано: 12 дек. 2023
Источник: nvd
CVSS3: 6.8
EPSS Низкий

Описание

OS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and earlier allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command by sending a specially crafted request to the product.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:elecom:wrc-x3000gsn_firmware:1.0.2:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x3000gsn:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:elecom:wrc-x3000gs_firmware:*:*:*:*:*:*:*:*
Версия до 1.0.24 (включая)
cpe:2.3:h:elecom:wrc-x3000gs:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:o:elecom:wrc-x3000gsa_firmware:*:*:*:*:*:*:*:*
Версия до 1.0.24 (включая)
cpe:2.3:h:elecom:wrc-x3000gsa:-:*:*:*:*:*:*:*

EPSS

Процентиль: 39%
0.00173
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-78
CWE-78

Связанные уязвимости

CVSS3: 6.8
github
около 2 лет назад

OS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and earlier allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command by sending a specially crafted request to the product.

EPSS

Процентиль: 39%
0.00173
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-78
CWE-78