8.8
CVE-2023-23912
- EPSS 1.74%
- Veröffentlicht 09.02.2023 20:15:11
- Zuletzt bearbeitet 24.03.2025 19:15:41
- Quelle support@hackerone.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with their DHCPv6 prefix delegation set to dhcpv6-stateless or dhcpv6-stateful, allows a malicious actor directly connected to the WAN interface of an affected device to create a remote code execution vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ui ≫ Usg Firmware Version < 4.4.57
Ui ≫ Usg-pro-4 Firmware Version < 4.4.57
Ui ≫ Er-10x Firmware Version < 2.0.9
Ui ≫ Er-10x Firmware Version2.0.9 Update-
Ui ≫ Er-10x Firmware Version2.0.9 Updatehotfix2
Ui ≫ Er-10x Firmware Version2.0.9 Updatehotfix4
Ui ≫ Er-10x Firmware Version2.0.9 Updatehotfix5
Ui ≫ Er-12 Firmware Version < 2.0.9
Ui ≫ Er-12 Firmware Version2.0.9 Update-
Ui ≫ Er-12 Firmware Version2.0.9 Updatehotfix2
Ui ≫ Er-12 Firmware Version2.0.9 Updatehotfix4
Ui ≫ Er-12 Firmware Version2.0.9 Updatehotfix5
Ui ≫ Er-12p Firmware Version < 2.0.9
Ui ≫ Er-12p Firmware Version2.0.9 Update-
Ui ≫ Er-12p Firmware Version2.0.9 Updatehotfix2
Ui ≫ Er-12p Firmware Version2.0.9 Updatehotfix4
Ui ≫ Er-12p Firmware Version2.0.9 Updatehotfix5
Ui ≫ Er-4 Firmware Version < 2.0.9
Ui ≫ Er-4 Firmware Version2.0.9 Update-
Ui ≫ Er-4 Firmware Version2.0.9 Updatehotfix2
Ui ≫ Er-4 Firmware Version2.0.9 Updatehotfix4
Ui ≫ Er-4 Firmware Version2.0.9 Updatehotfix5
Ui ≫ Er-6p Firmware Version < 2.0.9
Ui ≫ Er-6p Firmware Version2.0.9 Update-
Ui ≫ Er-6p Firmware Version2.0.9 Updatehotfix2
Ui ≫ Er-6p Firmware Version2.0.9 Updatehotfix4
Ui ≫ Er-6p Firmware Version2.0.9 Updatehotfix5
Ui ≫ Er-8-xg Firmware Version < 2.0.9
Ui ≫ Er-8-xg Firmware Version2.0.9 Update-
Ui ≫ Er-8-xg Firmware Version2.0.9 Updatehotfix2
Ui ≫ Er-8-xg Firmware Version2.0.9 Updatehotfix4
Ui ≫ Er-8-xg Firmware Version2.0.9 Updatehotfix5
Ui ≫ Er-x Firmware Version < 2.0.9
Ui ≫ Er-x Firmware Version2.0.9 Update-
Ui ≫ Er-x Firmware Version2.0.9 Updatehotfix2
Ui ≫ Er-x Firmware Version2.0.9 Updatehotfix4
Ui ≫ Er-x Firmware Version2.0.9 Updatehotfix5
Ui ≫ Er-x-sfp Firmware Version < 2.0.9
Ui ≫ Er-x-sfp Firmware Version2.0.9 Update-
Ui ≫ Er-x-sfp Firmware Version2.0.9 Updatehotfix2
Ui ≫ Er-x-sfp Firmware Version2.0.9 Updatehotfix4
Ui ≫ Er-x-sfp Firmware Version2.0.9 Updatehotfix5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.74% | 0.814 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-75 Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
The product does not adequately filter user-controlled input for special elements with control implications.
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.