9.8

CVE-2023-7077

Sharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X555UNV, X754HB, X554HB, E705, E805, E905, UN551S, UN551VS, X551UHD, X651UHD, X841UHD, X981UHD, MD551C8) allows an attacker execute remote code by sending unintended parameters in http request.

Data is provided by the National Vulnerability Database (NVD)
SharpNec E705 Firmware Version-
   SharpNec E705 Version-
SharpNec E805 Firmware Version-
   SharpNec E805 Version-
SharpNec E905 Firmware Version-
   SharpNec E905 Version-
SharpNec Md551c8 Firmware Version-
   SharpNec Md551c8 Version-
SharpNec P403 Firmware Version-
   SharpNec P403 Version-
SharpNec P463 Firmware Version-
   SharpNec P463 Version-
SharpNec P553 Firmware Version-
   SharpNec P553 Version-
SharpNec P703 Firmware Version-
   SharpNec P703 Version-
SharpNec P801 Firmware Version-
   SharpNec P801 Version-
SharpNec Un551s Firmware Version-
   SharpNec Un551s Version-
SharpNec Un551vs Firmware Version-
   SharpNec Un551vs Version-
SharpNec X464un Firmware Version-
   SharpNec X464un Version-
SharpNec X464uns Firmware Version-
   SharpNec X464uns Version-
SharpNec X464unv Firmware Version-
   SharpNec X464unv Version-
SharpNec X474hb Firmware Version-
   SharpNec X474hb Version-
SharpNec X551uhd Firmware Version-
   SharpNec X551uhd Version-
SharpNec X554hb Firmware Version-
   SharpNec X554hb Version-
SharpNec X554un Firmware Version-
   SharpNec X554un Version-
SharpNec X554uns Firmware Version-
   SharpNec X554uns Version-
SharpNec X554unv Firmware Version-
   SharpNec X554unv Version-
SharpNec X555uns Firmware Version-
   SharpNec X555uns Version-
SharpNec X555unv Firmware Version-
   SharpNec X555unv Version-
SharpNec X651uhd Firmware Version-
   SharpNec X651uhd Version-
SharpNec X754hb Firmware Version-
   SharpNec X754hb Version-
SharpNec X841uhd Firmware Version-
   SharpNec X841uhd Version-
SharpNec X981uhd Firmware Version-
   SharpNec X981uhd Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.75% 0.721
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.