HIGH · 7.2

CVE-2023-43744

An OS command injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an administrator to ...

Vulnerability Description

An OS command injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an administrator to execute arbitrary OS commands via a file name parameter in a patch application function. The Zultys MX Administrator client has a "Patch Manager" section that allows administrators to apply patches to the device. The user supplied filename for the patch file is passed to a shell script without validation. Including bash command substitution characters in a patch file name results in execution of the provided command.

CVSS Score

7.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ZultysMx-Se Firmware< 16.0.4
ZultysMx-Se-
ZultysMx-Se Ii Firmware< 16.0.4
ZultysMx-Se Ii-
ZultysMx-E Firmware< 16.0.4
ZultysMx-E-
ZultysMx-Virtual Firmware< 16.0.4
ZultysMx-Virtual-
ZultysMx250 Firmware< 16.0.4
ZultysMx250-
ZultysMx30 Firmware< 16.0.4
ZultysMx30-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-43744?

CVE-2023-43744 is a vulnerability with a CVSS score of 7.2 (HIGH). An OS command injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an administrator to ...

How severe is CVE-2023-43744?

CVE-2023-43744 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-43744?

Check the references section above for vendor advisories and patch information. Affected products include: Zultys Mx-Se Firmware, Zultys Mx-Se, Zultys Mx-Se Ii Firmware, Zultys Mx-Se Ii, Zultys Mx-E Firmware.