Lucene search

K
nvd[email protected]NVD:CVE-2023-24229
HistoryMar 15, 2023 - 6:15 p.m.

CVE-2023-24229

2023-03-1518:15:10
CWE-78
CWE-77
web.nvd.nist.gov
1
draytek vigor2960
v1.5.1.4
authenticated
os command injection
mainfunction.cgi

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0.003

Percentile

69.0%

DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands via the mainfunction.cgi ‘parameter’ parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Affected configurations

Nvd
Node
draytekvigor2960_firmwareMatch1.5.1.4
AND
draytekvigor2960Match-
VendorProductVersionCPE
draytekvigor2960_firmware1.5.1.4cpe:2.3:o:draytek:vigor2960_firmware:1.5.1.4:*:*:*:*:*:*:*
draytekvigor2960-cpe:2.3:h:draytek:vigor2960:-:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0.003

Percentile

69.0%

Related for NVD:CVE-2023-24229