8.8

CVE-2023-23912

Exploit

A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with their DHCPv6 prefix delegation set to dhcpv6-stateless or dhcpv6-stateful, allows a malicious actor directly connected to the WAN interface of an affected device to create a remote code execution vulnerability.

Data is provided by the National Vulnerability Database (NVD)
UiUsg Firmware Version < 4.4.57
   UiUsg Version-
UiUsg-pro-4 Firmware Version < 4.4.57
   UiUsg-pro-4 Version-
UiEr-10x Firmware Version < 2.0.9
   UiEr-10x Version-
UiEr-10x Firmware Version2.0.9 Update-
   UiEr-10x Version-
UiEr-10x Firmware Version2.0.9 Updatehotfix2
   UiEr-10x Version-
UiEr-10x Firmware Version2.0.9 Updatehotfix4
   UiEr-10x Version-
UiEr-10x Firmware Version2.0.9 Updatehotfix5
   UiEr-10x Version-
UiEr-12 Firmware Version < 2.0.9
   UiEr-12 Version-
UiEr-12 Firmware Version2.0.9 Update-
   UiEr-12 Version-
UiEr-12 Firmware Version2.0.9 Updatehotfix2
   UiEr-12 Version-
UiEr-12 Firmware Version2.0.9 Updatehotfix4
   UiEr-12 Version-
UiEr-12 Firmware Version2.0.9 Updatehotfix5
   UiEr-12 Version-
UiEr-12p Firmware Version < 2.0.9
   UiEr-12p Version-
UiEr-12p Firmware Version2.0.9 Update-
   UiEr-12p Version-
UiEr-12p Firmware Version2.0.9 Updatehotfix2
   UiEr-12p Version-
UiEr-12p Firmware Version2.0.9 Updatehotfix4
   UiEr-12p Version-
UiEr-12p Firmware Version2.0.9 Updatehotfix5
   UiEr-12p Version-
UiEr-4 Firmware Version < 2.0.9
   UiEr-4 Version-
UiEr-4 Firmware Version2.0.9 Update-
   UiEr-4 Version-
UiEr-4 Firmware Version2.0.9 Updatehotfix2
   UiEr-4 Version-
UiEr-4 Firmware Version2.0.9 Updatehotfix4
   UiEr-4 Version-
UiEr-4 Firmware Version2.0.9 Updatehotfix5
   UiEr-4 Version-
UiEr-6p Firmware Version < 2.0.9
   UiEr-6p Version-
UiEr-6p Firmware Version2.0.9 Update-
   UiEr-6p Version-
UiEr-6p Firmware Version2.0.9 Updatehotfix2
   UiEr-6p Version-
UiEr-6p Firmware Version2.0.9 Updatehotfix4
   UiEr-6p Version-
UiEr-6p Firmware Version2.0.9 Updatehotfix5
   UiEr-6p Version-
UiEr-8-xg Firmware Version < 2.0.9
   UiEr-8-xg Version-
UiEr-8-xg Firmware Version2.0.9 Update-
   UiEr-8-xg Version-
UiEr-8-xg Firmware Version2.0.9 Updatehotfix2
   UiEr-8-xg Version-
UiEr-8-xg Firmware Version2.0.9 Updatehotfix4
   UiEr-8-xg Version-
UiEr-8-xg Firmware Version2.0.9 Updatehotfix5
   UiEr-8-xg Version-
UiEr-x Firmware Version < 2.0.9
   UiEr-x Version-
UiEr-x Firmware Version2.0.9 Update-
   UiEr-x Version-
UiEr-x Firmware Version2.0.9 Updatehotfix2
   UiEr-x Version-
UiEr-x Firmware Version2.0.9 Updatehotfix4
   UiEr-x Version-
UiEr-x Firmware Version2.0.9 Updatehotfix5
   UiEr-x Version-
UiEr-x-sfp Firmware Version < 2.0.9
   UiEr-x-sfp Version-
UiEr-x-sfp Firmware Version2.0.9 Update-
   UiEr-x-sfp Version-
UiEr-x-sfp Firmware Version2.0.9 Updatehotfix2
   UiEr-x-sfp Version-
UiEr-x-sfp Firmware Version2.0.9 Updatehotfix4
   UiEr-x-sfp Version-
UiEr-x-sfp Firmware Version2.0.9 Updatehotfix5
   UiEr-x-sfp Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.74% 0.814
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-75 Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)

The product does not adequately filter user-controlled input for special elements with control implications.

CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.