HIGH · 8.8

CVE-2023-23295

Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as r...

Vulnerability Description

Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
KorenixJetwave 2212G Firmware1.3.t
KorenixJetwave 2212G-
KorenixJetwave 2212X Firmware1.3.0
KorenixJetwave 2212X-
KorenixJetwave 2212S Firmware1.3.0
KorenixJetwave 2212S-
KorenixJetwave 2211C Firmware< 1.6
KorenixJetwave 2211C-
KorenixJetwave 2411 Firmware< 1.5
KorenixJetwave 2411-
KorenixJetwave 2111 Firmware< 1.5
KorenixJetwave 2111-
KorenixJetwave 2411L Firmware< 1.6
KorenixJetwave 2411L-
KorenixJetwave 2111L Firmware< 1.6
KorenixJetwave 2111L-
KorenixJetwave 2414 Firmware< 1.4
KorenixJetwave 2414-
KorenixJetwave 2114 Firmware< 1.4
KorenixJetwave 2114-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-23295?

CVE-2023-23295 is a vulnerability with a CVSS score of 8.8 (HIGH). Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as r...

How severe is CVE-2023-23295?

CVE-2023-23295 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-23295?

Check the references section above for vendor advisories and patch information. Affected products include: Korenix Jetwave 2212G Firmware, Korenix Jetwave 2212G, Korenix Jetwave 2212X Firmware, Korenix Jetwave 2212X, Korenix Jetwave 2212S Firmware.