7.2
CVE-2023-1731
- EPSS 0.28%
- Veröffentlicht 24.04.2023 14:15:07
- Zuletzt bearbeitet 21.11.2024 07:39:47
- Quelle info@cert.vde.com
- CVE-Watchlists
- Unerledigt
In Meinbergs LTOS versions prior to V7.06.013, the configuration file upload function would not correctly validate the input, which would allow an remote authenticated attacker with high privileges to execute arbitrary commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Meinbergglobal ≫ Lantime Firmware Version < 7.06.013
Meinbergglobal ≫ Lantime M100 Version-
Meinbergglobal ≫ Lantime M200 Version-
Meinbergglobal ≫ Lantime M300 Version-
Meinbergglobal ≫ Lantime M400 Version-
Meinbergglobal ≫ Lantime M600 Version-
Meinbergglobal ≫ Lantime M900 Version-
Meinbergglobal ≫ Lantime M200 Version-
Meinbergglobal ≫ Lantime M300 Version-
Meinbergglobal ≫ Lantime M400 Version-
Meinbergglobal ≫ Lantime M600 Version-
Meinbergglobal ≫ Lantime M900 Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.507 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| info@cert.vde.com | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.