7.8
CVE-2023-46681
- EPSS 0.09%
- Veröffentlicht 26.12.2023 08:15:10
- Zuletzt bearbeitet 21.11.2024 08:29:03
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in VR-S1000 firmware Ver. 2.37 and earlier allows an authenticated attacker who can access to the product's command line interface to execute an arbitrary command.Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Buffalo ≫ Vr-s1000 Firmware Version <= 2.37
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.265 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.