Vulnerability Description
ZPE Systems, Inc Nodegrid OS v5.0.0 to v5.0.17, v5.2.0 to v5.2.19, v5.4.0 to v5.4.16, v5.6.0 to v5.6.13, v5.8.0 to v5.8.10, and v5.10.0 to v5.10.3 was discovered to contain a command injection vulnerability via the endpoint /v1/system/toolkit/files/.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zpesystems | Nodegrid Os | >= 5.0.0, < 5.0.18 |
Related Weaknesses (CWE)
References
- https://psirt.zpesystems.com/portal/en/kb/articles/security-advisory-zpe-ng-2023Vendor Advisory
- https://psirt.zpesystems.com/portal/en/kb/articles/security-advisory-zpe-ng-2023Vendor Advisory
FAQ
What is CVE-2023-43322?
CVE-2023-43322 is a vulnerability with a CVSS score of 8.8 (HIGH). ZPE Systems, Inc Nodegrid OS v5.0.0 to v5.0.17, v5.2.0 to v5.2.19, v5.4.0 to v5.4.16, v5.6.0 to v5.6.13, v5.8.0 to v5.8.10, and v5.10.0 to v5.10.3 was discovered to contain a command injection vulnera...
How severe is CVE-2023-43322?
CVE-2023-43322 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-43322?
Check the references section above for vendor advisories and patch information. Affected products include: Zpesystems Nodegrid Os.