Vulnerability Description
Multisuns EasyLog web+ has a code injection vulnerability. An unauthenticated remote attacker can exploit this vulnerability to inject code and access the system to perform arbitrary system operations or disrupt service.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Multisuns | Easylog Web\+ Firmware | 1.13.2.8 |
| Multisuns | Easylog Web\+ | - |
Related Weaknesses (CWE)
References
- https://www.twcert.org.tw/tw/cp-132-7605-2d86d-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-7605-2d86d-1.htmlThird Party Advisory
FAQ
What is CVE-2023-48390?
CVE-2023-48390 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Multisuns EasyLog web+ has a code injection vulnerability. An unauthenticated remote attacker can exploit this vulnerability to inject code and access the system to perform arbitrary system operation...
How severe is CVE-2023-48390?
CVE-2023-48390 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-48390?
Check the references section above for vendor advisories and patch information. Affected products include: Multisuns Easylog Web\+ Firmware, Multisuns Easylog Web\+.