Логотип exploitDog
bind:CVE-2023-4212
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-4212

Количество 2

Количество 2

nvd логотип

CVE-2023-4212

больше 2 лет назад

​A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-866w-mhv5-886h

больше 2 лет назад

?A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick.

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-4212

​A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick.

CVSS3: 6.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-866w-mhv5-886h

?A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick.

CVSS3: 6.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу