CVE-2023-1731
Summary
| CVE | CVE-2023-1731 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-24 14:15:00 UTC |
| Updated | 2023-05-23 06:15:00 UTC |
| Description | In Meinbergs LTOS versions prior to V7.06.013, the configuration file upload function would not correctly validate the input, which would allow an remote authenticated attacker with high privileges to execute arbitrary commands. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Meinbergglobal | Lantime Firmware | All | All | All | All |
| Hardware | Meinbergglobal | Lantime M100 | - | All | All | All |
| Hardware | Meinbergglobal | Lantime M200 | - | All | All | All |
| Hardware | Meinbergglobal | Lantime M300 | - | All | All | All |
| Hardware | Meinbergglobal | Lantime M400 | - | All | All | All |
| Hardware | Meinbergglobal | Lantime M600 | - | All | All | All |
| Hardware | Meinbergglobal | Lantime M900 | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Meinberg Security Advisory: [MBGSA-2023.02] LANTIME-Firmware V7.06.013 - Meinberg News | MISC | www.meinbergglobal.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.