Lucene search

K
cveJpcertCVE-2023-46681
HistoryDec 26, 2023 - 8:15 a.m.

CVE-2023-46681

2023-12-2608:15:10
CWE-88
jpcert
web.nvd.nist.gov
12
cve-2023-46681
vr-s1000
firmware
vulnerability
nvd
security
command injection

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0

Percentile

9.0%

Improper neutralization of argument delimiters in a command (‘Argument Injection’) vulnerability in VR-S1000 firmware Ver. 2.37 and earlier allows an authenticated attacker who can access to the product’s command line interface to execute an arbitrary command.

Affected configurations

Nvd
Vulners
Node
buffalovr-s1000_firmwareRange2.37
AND
buffalovr-s1000Match-
VendorProductVersionCPE
buffalovr-s1000_firmware*cpe:2.3:o:buffalo:vr-s1000_firmware:*:*:*:*:*:*:*:*
buffalovr-s1000-cpe:2.3:h:buffalo:vr-s1000:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "BUFFALO INC.",
    "product": "VR-S1000",
    "versions": [
      {
        "version": "firmware Ver. 2.37 and earlier",
        "status": "affected"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVE-2023-46681