ZeroHour

CVE-2023-38317

PoC
CVSS 3.1
9.8 critical
EPSS
1%p64
Published
()
Modified
Description

An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

Vendors
opennds
Products
opennds
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.