Vulnerability Description
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apsystems | Energy Communication Unit Firmware | c1.2.5 |
| Apsystems | Energy Communication Unit | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/171775/Altenergy-Power-Control-Software-C1.
- https://apsystems.comProduct
- https://github.com/ahmedalroky/Disclosures/blob/main/apesystems/os_command_injecExploitThird Party Advisory
- http://packetstormsecurity.com/files/171775/Altenergy-Power-Control-Software-C1.
- https://apsystems.comProduct
- https://github.com/ahmedalroky/Disclosures/blob/main/apesystems/os_command_injecExploitThird Party Advisory
FAQ
What is CVE-2023-28343?
CVE-2023-28343 is a vulnerability with a CVSS score of 9.8 (CRITICAL). OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_...
How severe is CVE-2023-28343?
CVE-2023-28343 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-28343?
Check the references section above for vendor advisories and patch information. Affected products include: Apsystems Energy Communication Unit Firmware, Apsystems Energy Communication Unit.