PT-2023-29125 · Byzoro+1 · Byzoro Smart S85F Management Platform+1

Rceraser

·

Published

2023-08-18

·

Updated

2024-05-17

·

CVE-2023-4414

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Byzoro Smart S85F Management Platform versions up to 20230807 Beijing Baichuo Smart S85F Management Platform versions up to 20230807
Description A critical issue has been found, affecting an unknown functionality of the file /log/decodmail.php. The manipulation of the file argument leads to command injection. This issue can be exploited remotely.
Recommendations For Byzoro Smart S85F Management Platform versions up to 20230807, consider restricting access to the /log/decodmail.php file until a patch is available. For Beijing Baichuo Smart S85F Management Platform versions up to 20230807, consider restricting access to the /log/decodmail.php file until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-4414

Affected Products

Beijing Baichuo Smart S85F Management Platform
Byzoro Smart S85F Management Platform