ZeroHour

CVE-2023-45852

PoC
CVSS 3.1
9.8 critical
EPSS
14%p96
Published
()
Modified
Description

In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method.

Vendors
viessmann
Products
vitogate 300 firmware
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.