PT-2023-26027 · Esds · Esds Emagic Data Center Management Suit

Chinamay Joshi

+2

·

Published

2023-08-08

·

Updated

2024-04-12

·

CVE-2023-37569

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ESDS Emagic Data Center Management Suit (affected versions not specified)
Description The issue is caused by a lack of input sanitization in the Ping component of the ESDS Emagic Data Center Management Suit. A remote authenticated attacker could exploit this by injecting OS commands on the targeted system, potentially allowing the execution of arbitrary code on the targeted system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-37569

Affected Products

Esds Emagic Data Center Management Suit