CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
48.5%
Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all versions allows a attacker to execute an arbitrary OS command with the root privilege, after obtaining a high privilege exploiting CVE-2023-3330 and CVE-2023-3331 vulnerabilities.
Vendor | Product | Version | CPE |
---|---|---|---|
nec | aterm_wf300hp_firmware | - | cpe:2.3:o:nec:aterm_wf300hp_firmware:-:*:*:*:*:*:*:* |
nec | aterm_wf300hp | - | cpe:2.3:h:nec:aterm_wf300hp:-:*:*:*:*:*:*:* |
nec | aterm_wg1400hp_firmware | - | cpe:2.3:o:nec:aterm_wg1400hp_firmware:-:*:*:*:*:*:*:* |
nec | aterm_wg1400hp | - | cpe:2.3:h:nec:aterm_wg1400hp:-:*:*:*:*:*:*:* |
nec | aterm_wg1800hp_firmware | - | cpe:2.3:o:nec:aterm_wg1800hp_firmware:-:*:*:*:*:*:*:* |
nec | aterm_wg1800hp | - | cpe:2.3:h:nec:aterm_wg1800hp:-:*:*:*:*:*:*:* |
nec | aterm_wg1800hp2_firmware | - | cpe:2.3:o:nec:aterm_wg1800hp2_firmware:-:*:*:*:*:*:*:* |
nec | aterm_wg1800hp2 | - | cpe:2.3:h:nec:aterm_wg1800hp2:-:*:*:*:*:*:*:* |
nec | aterm_wg2200hp_firmware | - | cpe:2.3:o:nec:aterm_wg2200hp_firmware:-:*:*:*:*:*:*:* |
nec | aterm_wg2200hp | - | cpe:2.3:h:nec:aterm_wg2200hp:-:*:*:*:*:*:*:* |
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
48.5%