PT-2023-22963 · Kb-Ahr08D+3 · Kb-Ahr08D+5
Published
2023-06-13
·
Updated
2025-01-03
·
CVE-2023-30764
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
KB-AHR04D versions prior to 91110.1.101106.78
KB-AHR08D versions prior to 91210.1.101106.78
KB-AHR16D versions prior to 91310.1.101106.78
KB-IRIP04A versions prior to 95110.1.100290.78A
KB-IRIP08A versions prior to 95210.1.100290.78A
KB-IRIP16A versions prior to 95310.1.100290.78A
Description
An OS command injection issue exists in the KB-AHR series and KB-IRIP series, allowing an arbitrary OS command to be executed on the product or the device settings to be altered if exploited.
Recommendations
For KB-AHR04D versions prior to 91110.1.101106.78, update to a version 91110.1.101106.78 or later.
For KB-AHR08D versions prior to 91210.1.101106.78, update to a version 91210.1.101106.78 or later.
For KB-AHR16D versions prior to 91310.1.101106.78, update to a version 91310.1.101106.78 or later.
For KB-IRIP04A versions prior to 95110.1.100290.78A, update to a version 95110.1.100290.78A or later.
For KB-IRIP08A versions prior to 95210.1.100290.78A, update to a version 95210.1.100290.78A or later.
For KB-IRIP16A versions prior to 95310.1.100290.78A, update to a version 95310.1.100290.78A or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kb-Ahr04D
Kb-Ahr08D
Kb-Ahr16D
Kb-Irip04A
Kb-Irip08A
Kb-Irip16A