PT-2023-28635 · Frauscher Sensortechnik Gmbh · Fds101

CVE-2023-4291

·

Publicado

2023-09-20

·

Atualizado

2023-09-22

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi versions 1.4.24 and all previous versions
Description The issue is a remote code execution (RCE) vulnerability that can be exploited via manipulated parameters of the web interface without authentication, potentially leading to a full compromise of the FDS101 device.
Recommendations For versions 1.4.24 and all previous versions, consider disabling access to the web interface until a patch is available to prevent exploitation of the RCE vulnerability. Restrict access to the device to minimize the risk of compromise. Avoid using manipulated parameters in the web interface to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-4291

Produtos afetados

Fds101