ZeroHour

CVE-2023-38323

PoC
CVSS 3.1
9.8 critical
EPSS
1%p64
Published
()
Modified
Description

An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

Vendors
opennds
Products
opennds
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.