PT-2023-6631 · Octoprint · Octoprint
Rggu2Zr
·
Published
2023-10-09
·
Updated
2023-10-13
·
CVE-2023-41047
CVSS v4.0
8.4
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OctoPrint versions up to and including 1.9.2
Description
The issue allows malicious administrators to configure a specially crafted GCODE script, enabling code execution during the rendering of that script. This could be used to extract or manipulate data managed by OctoPrint, as well as execute arbitrary commands with the rights of the OctoPrint process on the server system. More than 20,000 OctoPrint instances are currently accessible online.
Recommendations
For OctoPrint versions up to and including 1.9.2, update to version 1.9.3 or later to resolve the issue.
As a temporary workaround, consider restricting access to the GCODE script configuration to trusted administrators only, and avoid configuring arbitrary GCODE scripts found online or provided by third parties.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Octoprint