PT-2023-25981 · Casaos · Casaos

Kevin Stubbings

+1

·

Publicado

2023-08-24

·

Atualizado

2024-08-21

·

CVE-2023-37469

CVSS v4.0

9.3

Crítica

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions CasaOS versions prior to 0.4.4
Description CasaOS is an open-source personal cloud system. If an authenticated user is able to successfully connect to a controlled SMB server, they are able to execute arbitrary commands.
Recommendations For versions prior to 0.4.4, update to version 0.4.4 to resolve the issue. As a temporary workaround, consider restricting access to controlled SMB servers until the update is applied.

Exploit

Correção

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-37469
GHSA-92VC-4FCW-G68Q
GO-2023-2026

Produtos afetados

Casaos