Lucene search

K
cveMitreCVE-2023-41109
HistoryAug 28, 2023 - 8:15 p.m.

CVE-2023-41109

2023-08-2820:15:08
CWE-78
mitre
web.nvd.nist.gov
16
cve-2023-41109
smartnode sn200
unauthenticated
os command injection
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.36

Percentile

97.2%

SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection.

Affected configurations

Nvd
Node
pattonsmartnode_sn200Match-
AND
pattonsmartnode_sn200_firmwareRange3.21.2-23021
VendorProductVersionCPE
pattonsmartnode_sn200-cpe:2.3:h:patton:smartnode_sn200:-:*:*:*:*:*:*:*
pattonsmartnode_sn200_firmware*cpe:2.3:o:patton:smartnode_sn200_firmware:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.36

Percentile

97.2%