PT-2023-8530 · Buffalo · Buffalo Vr-S1000
Samy Younsi
+1
·
Published
2023-12-26
·
Updated
2024-01-04
·
CVE-2023-46681
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BUFFALO VR-S1000 versions 2.37 and earlier
Description
The issue is related to the improper neutralization of argument delimiters in a command, also known as an 'Argument Injection' vulnerability. This allows an authenticated attacker who can access the product's command line interface to execute an arbitrary command.
Recommendations
For versions 2.37 and earlier, consider restricting access to the command line interface until a patch is available. As a temporary workaround, limit the execution of commands to only those that are necessary for the device's operation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Buffalo Vr-S1000