PT-2024-14918 · Brivo · Brivo Acs100+1
Gabe Siftar
+1
·
Published
2024-02-19
·
Updated
2025-02-05
·
CVE-2023-6260
CVSS v3.1
9.0
Critical
| Vector | AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Brivo ACS100 versions 5.2.4 through 6.2.4.3
Brivo ACS300 versions 5.2.4 through 6.2.4.3
Description
The issue is related to an OS Command Injection vulnerability, allowing attackers to bypass physical security. This vulnerability affects both network adjacent access and physical access systems.
Recommendations
For Brivo ACS100 versions 5.2.4 through 6.2.4.3, update to version 6.2.4.3 or later to resolve the issue.
For Brivo ACS300 versions 5.2.4 through 6.2.4.3, update to version 6.2.4.3 or later to resolve the issue.
As a temporary workaround, consider restricting access to vulnerable systems to minimize the risk of exploitation.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Brivo Acs100
Brivo Acs300