PT-2024-12710 · Opennds+1 · Opennds+1

Published

2024-01-25

·

Updated

2024-02-02

·

CVE-2023-38319

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenNDS versions prior to 10.1.3
Description An issue was discovered in OpenNDS where it fails to sanitize the FAS key entry in the configuration file. This allows attackers with direct or indirect access to the configuration file to execute arbitrary OS commands.
Recommendations For versions prior to 10.1.3, update to version 10.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the configuration file to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-38319

Affected Products

Debian
Opennds