PT-2023-18412 · Pix-Rt100 · Pix-Rt100

·

CVE-2023-22304

·

Published

2023-01-17

·

Updated

2025-04-04

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PIX-RT100 versions RT100 TEQ 2.1.1 EQ101 and RT100 TEQ 2.1.2 EQ101
Description The issue allows a network-adjacent attacker who can access product settings to execute an arbitrary OS command. This is an OS command injection vulnerability.
Recommendations For PIX-RT100 version RT100 TEQ 2.1.1 EQ101, update to a version that fixes the OS command injection vulnerability. For PIX-RT100 version RT100 TEQ 2.1.2 EQ101, update to a version that fixes the OS command injection vulnerability. As a temporary workaround, consider restricting access to product settings to minimize the risk of exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-22304

Affected Products

Pix-Rt100