Lucene search

K
cve[email protected]CVE-2023-40144
HistoryAug 23, 2023 - 4:15 a.m.

CVE-2023-40144

2023-08-2304:15:10
CWE-78
web.nvd.nist.gov
38
cve-2023-40144
os command injection
cbc products
remote attacker
authenticated
arbitrary command
device settings
vulnerability
nvd

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.9%

OS command injection vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H, NR16H series and DR-16F, DR-8F, DR-4F, DR-16H, DR-8H, DR-4H, DR-4M41 series are no longer supported, therefore updates for those products are not provided.

Affected configurations

NVD
Node
cbcnr4hMatch-
AND
cbcnr4h_firmwareMatch-
Node
cbcnr8hMatch-
AND
cbcnr8h_firmwareMatch-
Node
cbcnr16hMatch-
AND
cbcnr16h_firmwareMatch-
Node
cbcdr-16f42aMatch-
AND
cbcdr-16f42a_firmwareMatch-
Node
cbcdr-16f45atMatch-
AND
cbcdr-16f45at_firmwareMatch-
Node
cbcdr-8f42aMatch-
AND
cbcdr-8f42a_firmwareMatch-
Node
cbcdr-8f45at_firmwareMatch-
AND
cbcdr-8f45atMatch-
Node
cbcdr-4fx1_firmwareMatch-
AND
cbcdr-4fx1Match-
Node
cbcdr-16h_firmwareMatch-
AND
cbcdr-16hMatch-
Node
cbcdr-8h_firmwareMatch-
AND
cbcdr-8hMatch-
Node
cbcdr-4h_firmwareMatch-
AND
cbcdr-4hMatch-
Node
cbcdrh8-4m41-a_firmwareMatch-
AND
cbcdrh8-4m41-aMatch-
Node
cbcnr8-4m71_firmwareMatch-
AND
cbcnr8-4m71Match-
Node
cbcnr8-8m72_firmwareMatch-
AND
cbcnr8-8m72Match-
Node
cbcnr-16m_firmwareMatch-
AND
cbcnr-16mMatch-
Node
cbcnr-16f85-8pra_firmwareMatch-
AND
cbcnr-16f85-8praMatch-
Node
cbcnr-16f82-16p_firmwareMatch-
AND
cbcnr-16f82-16pMatch-
Node
cbcnr-4f_firmwareMatch-
AND
cbcnr-4fMatch-
Node
cbcnr-8f_firmwareMatch-
AND
cbcnr-8fMatch-
Node
cbcdr-16m52_firmwareMatch-
AND
cbcdr-16m52Match-
Node
cbcdr-16m52-av_firmwareMatch-
AND
cbcdr-16m52-avMatch-
Node
cbcdr-8m52-av_firmwareMatch-
AND
cbcdr-8m52-avMatch-
Node
cbcdr-4m51-av_firmwareMatch-
AND
cbcdr-4m51-avMatch-
CPENameOperatorVersion
cbc:nr4h_firmwarecbc nr4h firmwareeq-

CNA Affected

[
  {
    "vendor": "CBC Co.,Ltd.",
    "product": "NR4H, NR8H, NR16H series",
    "versions": [
      {
        "version": "firmware all versions",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "CBC Co.,Ltd.",
    "product": "DR-16F, DR-8F, DR-4F, DR-16H, DR-8H, DR-4H, DR-4M41 series",
    "versions": [
      {
        "version": "firmware all versions",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "CBC Co.,Ltd.",
    "product": "NR-4M, NR-8M, NR-16M series",
    "versions": [
      {
        "version": "firmware all versions",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "CBC Co.,Ltd.",
    "product": "NR-4F, NR-8F, NR-16F series",
    "versions": [
      {
        "version": "firmware all versions",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "CBC Co.,Ltd.",
    "product": "DR-16M, DR-8M, DR-4M51 series",
    "versions": [
      {
        "version": "firmware all versions",
        "status": "affected"
      }
    ]
  }
]

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.9%

Related for CVE-2023-40144