7.2

CVE-2023-1731

In Meinbergs LTOS versions prior to V7.06.013, the configuration file upload function would not correctly validate the input, which would allow an remote authenticated attacker with high privileges to execute arbitrary commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MeinbergglobalLantime Firmware Version < 7.06.013
   MeinbergglobalLantime M100 Version-
   MeinbergglobalLantime M200 Version-
   MeinbergglobalLantime M300 Version-
   MeinbergglobalLantime M400 Version-
   MeinbergglobalLantime M600 Version-
   MeinbergglobalLantime M900 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.507
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
info@cert.vde.com 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.