Aller au contenu

Fiche vulnérabilité

CVE-2023-47802 : faille élevée Synology Camera Firmware (CVSS 7.2)

Description

A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the IP block functionality. This allows remote authenticated users with administrator privileges to execute arbitrary commands via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.

En bref

Sévérité
Élevée (CVSS 7.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
28 juin 2024
Dernière mise à jour
2 août 2024

Produits concernés

  • Synology Camera Firmware

Références

Rechercher une autre vulnérabilité dans la base CVE