9.8

CVE-2023-22581

White Rabbit Switch - Unauthenticated remote code execution

White Rabbit Switch contains a vulnerability which makes it possible for an attacker to perform system commands under the context of the web application (the default installation makes the webserver run as the root user).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Home.CernWhite Rabbit Switch Firmware Version <= 6.0.1
   Home.CernWhite Rabbit Switch Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.69% 0.48
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
csirt@divd.nl 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://csirt.divd.nl/DIVD-2022-00068/
Broken Link
https://csirt.divd.nl/CVE-2023-22581/
Broken Link
https://vuldb.com/?id.227269
Third Party Advisory