Lucene search

K
nvd[email protected]NVD:CVE-2023-40158
HistoryAug 23, 2023 - 3:15 a.m.

CVE-2023-40158

2023-08-2303:15:08
web.nvd.nist.gov
2
cbc products
remote attacker
os command execution
settings alteration
vulnerability
authentication
affected products
vendor
unsupported products
cve-2023-40158

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.8%

Hidden functionality vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H, NR16H series and DR-16F, DR-8F, DR-4F, DR-16H, DR-8H, DR-4H, DR-4M41 series are no longer supported, therefore updates for those products are not provided.

Affected configurations

NVD
Node
cbcnr4h_firmwareMatch-
AND
cbcnr4hMatch-
Node
cbcnr8h_firmwareMatch-
AND
cbcnr8hMatch-
Node
cbcnr16h_firmwareMatch-
AND
cbcnr16hMatch-
Node
cbcdr-16f42a_firmwareMatch-
AND
cbcdr-16f42aMatch-
Node
cbcdr-16f45at_firmwareMatch-
AND
cbcdr-16f45atMatch-
Node
cbcdr-8f42a_firmwareMatch-
AND
cbcdr-8f42aMatch-
Node
cbcdr-8f45at_firmwareMatch-
AND
cbcdr-8f45atMatch-
Node
cbcdr-4fx1_firmwareMatch-
AND
cbcdr-4fx1Match-
Node
cbcdr-16h_firmwareMatch-
AND
cbcdr-16hMatch-
Node
cbcdr-8h_firmwareMatch-
AND
cbcdr-8hMatch-
Node
cbcdr-4h_firmwareMatch-
AND
cbcdr-4hMatch-
Node
cbcdrh8-4m41-a_firmwareMatch-
AND
cbcdrh8-4m41-aMatch-
Node
cbcnr8-4m71_firmwareMatch-
AND
cbcnr8-4m71Match-
Node
cbcnr8-8m72_firmwareMatch-
AND
cbcnr8-8m72Match-
Node
cbcnr-16m_firmwareMatch-
AND
cbcnr-16mMatch-
Node
cbcnr-16f85-8pra_firmwareMatch-
AND
cbcnr-16f85-8praMatch-
Node
cbcnr-16f82-16p_firmwareMatch-
AND
cbcnr-16f82-16pMatch-
Node
cbcnr-4f_firmwareMatch-
AND
cbcnr-4fMatch-
Node
cbcnr-8f_firmwareMatch-
AND
cbcnr-8fMatch-
Node
cbcdr-16m52_firmwareMatch-
AND
cbcdr-16m52Match-
Node
cbcdr-16m52-av_firmwareMatch-
AND
cbcdr-16m52-avMatch-
Node
cbcdr-8m52-av_firmwareMatch-
AND
cbcdr-8m52-avMatch-
Node
cbcdr-4m51-av_firmwareMatch-
AND
cbcdr-4m51-avMatch-

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.8%

Related for NVD:CVE-2023-40158