CVE-2023-0432
Summary
| CVE | CVE-2023-0432 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-31 16:15:00 UTC |
| Updated | 2023-11-07 04:00:00 UTC |
| Description | The web configuration service of the affected device contains an authenticated command injection vulnerability. It can be used to execute system commands on the operating system (OS) from the device in the context of the user "root." If the attacker has credentials for the web service, then the device could be fully compromised. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Deltaww | Dx-2100l1-cn | - | All | All | All |
| Operating System | Deltaww | Dx-2100l1-cn Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Delta Electronics DX-2100-L1-CN | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.