Vulnerability Description
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Contec | Solarview Compact Firmware | <= 6.00 |
| Contec | Solarview Compact | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/174537/SolarView-Compact-6.00-Remote-Comman
- https://github.com/Timorlover/CVE-2023-23333ExploitThird Party Advisory
- http://packetstormsecurity.com/files/174537/SolarView-Compact-6.00-Remote-Comman
- https://github.com/Timorlover/CVE-2023-23333ExploitThird Party Advisory
FAQ
What is CVE-2023-23333?
CVE-2023-23333 is a vulnerability with a CVSS score of 9.8 (CRITICAL). There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.
How severe is CVE-2023-23333?
CVE-2023-23333 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-23333?
Check the references section above for vendor advisories and patch information. Affected products include: Contec Solarview Compact Firmware, Contec Solarview Compact.