Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform /importexport.php विशेषाधिकार वाढीचे प्रमाण वाढले

एक असुरक्षितता जी गंभीर म्हणून वर्गीकृत आहे, ती Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform जोपर्यंत 20230906 मध्ये आढळली आहे. प्रभावित आहे अज्ञात फंक्शन फाइल /importexport.php च्या. सॉफ्टवेअरमध्ये sql या आर्ग्युमेंटमध्ये वापर विशेषाधिकार वाढीचे प्रमाण वाढले घडवून आणतो. CWE वापरून समस्या घोषित केल्याने CWE-78 कडे नेले जाते. कमजोरी प्रकाशित करण्यात आली होती 09/09/2023. सल्ला डाउनलोडसाठी github.com येथे शेअर केला आहे. ही कमतरता CVE-2023-4873 या नावाने ओळखली जाते. हल्ला दूरस्थपणे सुरू करणे शक्य आहे. तांत्रिक तपशील उपलब्ध आहेत. यासाठी एक एक्स्प्लॉइट उपलब्ध आहे. शोषण सार्वजनिकपणे उघड झाले आहे आणि वापरले जाऊ शकते. सध्याच्या घडीला अंदाजे USD $0-$5k असू शकतो. MITRE ATT&CK प्रकल्पाने हल्ल्याची तंत्रज्ञान T1202 म्हणून घोषित केली आहे. हे प्रूफ-ऑफ-कॉन्सेप्ट म्हणून घोषित केले आहे. github.com या ठिकाणी शोषण डाउनलोडसाठी शेअर केले आहे. 0-डे म्हणून अंदाजे अंडरग्राउंड किंमत सुमारे $0-$5k होती. VulDB is the best source for vulnerability data and more expert information about this specific topic.

5 बदल · 88 डेटा पॉइंट्स

शेततयार केली
09/09/2023 10:24 AM
अद्ययावत 1/4
04/10/2023 04:33 PM
अद्ययावत 2/4
04/10/2023 04:41 PM
अद्ययावत 3/4
09/04/2024 09:06 AM
अद्ययावत 4/4
25/06/2025 05:28 PM
cvss3_vuldb_iLLLLL
cvss3_vuldb_aLLLLL
cvss3_vuldb_ePPPPP
cvss3_vuldb_rcRRRRR
advisory_urlhttps://github.com/cugerQDHJ/cve/blob/main/rce.mdhttps://github.com/cugerQDHJ/cve/blob/main/rce.mdhttps://github.com/cugerQDHJ/cve/blob/main/rce.mdhttps://github.com/cugerQDHJ/cve/blob/main/rce.mdhttps://github.com/cugerQDHJ/cve/blob/main/rce.md
exploit_availability11111
exploit_publicity11111
exploit_urlhttps://github.com/cugerQDHJ/cve/blob/main/rce.mdhttps://github.com/cugerQDHJ/cve/blob/main/rce.mdhttps://github.com/cugerQDHJ/cve/blob/main/rce.mdhttps://github.com/cugerQDHJ/cve/blob/main/rce.mdhttps://github.com/cugerQDHJ/cve/blob/main/rce.md
source_cveCVE-2023-4873CVE-2023-4873CVE-2023-4873CVE-2023-4873CVE-2023-4873
cna_responsibleVulDBVulDBVulDBVulDBVulDB
software_vendorBeijing BaichuoBeijing BaichuoBeijing BaichuoByzoroByzoro
software_nameSmart S45F Multi-Service Secure Gateway Intelligent Management PlatformSmart S45F Multi-Service Secure Gateway Intelligent Management PlatformSmart S45F Multi-Service Secure Gateway Intelligent Management PlatformSmart S45F Multi-Service Secure Gateway Intelligent Management PlatformSmart S45F Multi-Service Secure Gateway Intelligent Management Platform
software_version<=20230906<=20230906<=20230906<=20230906<=20230906
software_file/importexport.php/importexport.php/importexport.php/importexport.php/importexport.php
software_argumentsqlsqlsqlsqlsql
vulnerability_cweCWE-78 (विशेषाधिकार वाढीचे प्रमाण वाढले)CWE-78 (विशेषाधिकार वाढीचे प्रमाण वाढले)CWE-78 (विशेषाधिकार वाढीचे प्रमाण वाढले)CWE-78 (विशेषाधिकार वाढीचे प्रमाण वाढले)CWE-78 (विशेषाधिकार वाढीचे प्रमाण वाढले)
vulnerability_risk22222
cvss3_vuldb_avNNNNN
cvss3_vuldb_acLLLLL
cvss3_vuldb_uiNNNNN
cvss3_vuldb_sUUUUU
cvss3_vuldb_cLLLLL
advisory_date1694210400 (09/09/2023)1694210400 (09/09/2023)1694210400 (09/09/2023)1694210400 (09/09/2023)1694210400 (09/09/2023)
cvss2_vuldb_avNNNNN
cvss2_vuldb_acLLLLL
cvss2_vuldb_ciPPPPP
cvss2_vuldb_iiPPPPP
cvss2_vuldb_aiPPPPP
cvss2_vuldb_ePOCPOCPOCPOCPOC
cvss2_vuldb_rcURURURURUR
cvss2_vuldb_auSSSSS
cvss2_vuldb_rlNDNDNDNDND
cvss3_vuldb_prLLLLL
cvss3_vuldb_rlXXXXX
cvss2_vuldb_basescore6.56.56.56.56.5
cvss2_vuldb_tempscore5.65.65.65.65.6
cvss3_vuldb_basescore6.36.36.36.36.3
cvss3_vuldb_tempscore5.75.75.75.75.7
cvss3_meta_basescore6.36.37.57.57.5
cvss3_meta_tempscore5.75.77.37.37.3
price_0day$0-$5k$0-$5k$0-$5k$0-$5k$0-$5k
cve_assigned1694210400 (09/09/2023)1694210400 (09/09/2023)1694210400 (09/09/2023)1694210400 (09/09/2023)
cve_nvd_summaryA vulnerability, which was classified as critical, was found in Beijing Baichuo Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230906. Affected is an unknown function of the file /importexport.php. The manipulation of the argument sql leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-239358 is the identifier assigned to this vulnerability.A vulnerability, which was classified as critical, was found in Beijing Baichuo Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230906. Affected is an unknown function of the file /importexport.php. The manipulation of the argument sql leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-239358 is the identifier assigned to this vulnerability.A vulnerability, which was classified as critical, was found in Beijing Baichuo Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230906. Affected is an unknown function of the file /importexport.php. The manipulation of the argument sql leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-239358 is the identifier assigned to this vulnerability.A vulnerability, which was classified as critical, was found in Beijing Baichuo Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230906. Affected is an unknown function of the file /importexport.php. The manipulation of the argument sql leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-239358 is the identifier assigned to this vulnerability.
cvss3_nvd_avNNN
cvss3_nvd_acLLL
cvss3_nvd_prNNN
cvss3_nvd_uiNNN
cvss3_nvd_sUUU
cvss3_nvd_cHHH
cvss3_nvd_iHHH
cvss3_nvd_aHHH
cvss2_nvd_avNNN
cvss2_nvd_acLLL
cvss2_nvd_auSSS
cvss2_nvd_ciPPP
cvss2_nvd_iiPPP
cvss2_nvd_aiPPP
cvss3_cna_avNNN
cvss3_cna_acLLL
cvss3_cna_prLLL
cvss3_cna_uiNNN
cvss3_cna_sUUU
cvss3_cna_cLLL
cvss3_cna_iLLL
cvss3_cna_aLLL
cve_cnaVulDBVulDBVulDB
cvss2_nvd_basescore6.56.56.5
cvss3_nvd_basescore9.89.89.8
cvss3_cna_basescore6.36.36.3
cvss4_vuldb_avNN
cvss4_vuldb_acLL
cvss4_vuldb_prLL
cvss4_vuldb_uiNN
cvss4_vuldb_vcLL
cvss4_vuldb_viLL
cvss4_vuldb_vaLL
cvss4_vuldb_ePP
cvss4_vuldb_atNN
cvss4_vuldb_scNN
cvss4_vuldb_siNN
cvss4_vuldb_saNN
cvss4_vuldb_bscore5.35.3
cvss4_vuldb_btscore2.12.1
euvd_idEUVD-2023-54712

Might our Artificial Intelligence support you?

Check our Alexa App!