Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2023-24229
HistoryMar 15, 2023 - 12:00 a.m.

CVE-2023-24229

2023-03-1500:00:00
mitre
github.com
2
draytek vigor2960
os command injection
mainfunction.cgi

AI Score

6.9

Confidence

Low

EPSS

0.003

Percentile

69.0%

SSVC

Exploitation

poc

Automatable

no

Technical Impact

total

DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands via the mainfunction.cgi ‘parameter’ parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:o:draytek:vigor2960_firmware:1.5.1.4:*:*:*:*:*:*:*"
    ],
    "vendor": "draytek",
    "product": "vigor2960_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "1.5.1.4"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

6.9

Confidence

Low

EPSS

0.003

Percentile

69.0%

SSVC

Exploitation

poc

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2023-24229