cve/2023/CVE-2023-40158.md

22 lines
1.4 KiB
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2023-40158](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40158)
![](https://img.shields.io/static/v1?label=Product&message=DR-16F%2C%20DR-8F%2C%20DR-4F%2C%20DR-16H%2C%20DR-8H%2C%20DR-4H%2C%20DR-4M41%20series&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=DR-16M%2C%20DR-8M%2C%20DR-4M51%20series&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=NR-4F%2C%20NR-8F%2C%20NR-16F%20series&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=NR-4M%2C%20NR-8M%2C%20NR-16M%20series&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=NR4H%2C%20NR8H%2C%20NR16H%20series&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20firmware%20all%20versions%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Hidden%20Functionality&color=brighgreen)
### Description
Hidden functionality vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H, NR16H series and DR-16F, DR-8F, DR-4F, DR-16H, DR-8H, DR-4H, DR-4M41 series are no longer supported, therefore updates for those products are not provided.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds