PT-2024-13448 · Cypress Solutions · Ctm-200

Published

2024-03-07

·

Updated

2025-09-18

·

CVE-2023-47415

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cypress Solutions CTM-200 versions 2.7.1.5600 and below
Description The issue is related to an OS command injection vulnerability. This vulnerability can be exploited via the cli text parameter.
Recommendations For versions 2.7.1.5600 and below, avoid using the cli text parameter until a fix is available. As a temporary workaround, consider restricting access to the vulnerable parameter to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-47415

Affected Products

Ctm-200