9.8
CVE-2024-28015
- EPSS 0.79%
- Veröffentlicht 28.03.2024 01:15:47
- Zuletzt bearbeitet 29.09.2025 12:59:48
- Quelle psirt-info@cyber.jp.nec.com
- Teams Watchlist Login
- Unerledigt Login
Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker to execute an arbitrary OS command with the root privilege via the internet.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nec ≫ Aterm Wg1800hp4 Firmware Version-
Nec ≫ Aterm Wg1200hs3 Firmware Version-
Nec ≫ Aterm Wg1900hp2 Firmware Version-
Nec ≫ Aterm Wg1200hp3 Firmware Version-
Nec ≫ Aterm Wg1800hp3 Firmware Version-
Nec ≫ Aterm Wr7850s Firmware Version-
Nec ≫ Aterm Wr6650s Firmware Version-
Nec ≫ Aterm Wr6600h Firmware Version-
Nec ≫ Aterm Wr7800h Firmware Version-
Nec ≫ Aterm Wm3400rn Firmware Version-
Nec ≫ Aterm Wm3450rn Firmware Version-
Nec ≫ Aterm Wm3500r Firmware Version-
Nec ≫ Aterm Wm3600r Firmware Version-
Nec ≫ Aterm Wm3800r Firmware Version-
Nec ≫ Aterm Wr8166n Firmware Version-
Nec ≫ Aterm Mr01ln Firmware Version-
Nec ≫ Aterm Mr02ln Firmware Version-
Nec ≫ Aterm Wg1810hp(je) Firmware Version-
Nec ≫ Aterm Wg1810hp(mf) Firmware Version-
Nec ≫ Aterm Wg1200hs2 Firmware Version-
Nec ≫ Aterm Wg1900hp Firmware Version-
Nec ≫ Aterm Wg1200hp2 Firmware Version-
Nec ≫ Aterm W1200ex-ms Firmware Version-
Nec ≫ Aterm Wg1200hs Firmware Version-
Nec ≫ Aterm Wg1200hp Firmware Version-
Nec ≫ Aterm Wf300hp2 Firmware Version-
Nec ≫ Aterm W300p Firmware Version-
Nec ≫ Aterm Wf800hp Firmware Version-
Nec ≫ Aterm Wr8165n Firmware Version-
Nec ≫ Aterm Wg2200hp Firmware Version-
Nec ≫ Aterm Wf1200hp2 Firmware Version-
Nec ≫ Aterm Wg1800hp2 Firmware Version-
Nec ≫ Aterm Wf1200hp Firmware Version-
Nec ≫ Aterm Wg600hp Firmware Version-
Nec ≫ Aterm Wg300hp Firmware Version-
Nec ≫ Aterm Wf300hp Firmware Version-
Nec ≫ Aterm Wg1800hp Firmware Version-
Nec ≫ Aterm Wg1400hp Firmware Version-
Nec ≫ Aterm Wr8175n Firmware Version-
Nec ≫ Aterm Wr9300n Firmware Version-
Nec ≫ Aterm Wr8750n Firmware Version-
Nec ≫ Aterm Wr8160n Firmware Version-
Nec ≫ Aterm Wr9500n Firmware Version-
Nec ≫ Aterm Wr8600n Firmware Version-
Nec ≫ Aterm Wr8370n Firmware Version-
Nec ≫ Aterm Wr8170n Firmware Version-
Nec ≫ Aterm Wr8700n Firmware Version-
Nec ≫ Aterm Wr8300n Firmware Version-
Nec ≫ Aterm Wr8150n Firmware Version-
Nec ≫ Aterm Wr4100n Firmware Version-
Nec ≫ Aterm Wr4500n Firmware Version-
Nec ≫ Aterm Wr8100n Firmware Version-
Nec ≫ Aterm Wr8500n Firmware Version-
Nec ≫ Aterm Cr2500p Firmware Version-
Nec ≫ Aterm Wr8400n Firmware Version-
Nec ≫ Aterm Wr8200n Firmware Version-
Nec ≫ Aterm Wr1200h Firmware Version-
Nec ≫ Aterm Wr7870s Firmware Version-
Nec ≫ Aterm Wr6670s Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.79% | 0.731 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.