gist.github.comexploit
https://gist.github.com/xbz0n/674af0e802efaaafe90d2f67464c2690 CVE-2023-0830
MEDIUM
EasyNAS backup.pl system os command injection
Record summary
CVE-2023-0830 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
A vulnerability classified as critical has been found in EasyNAS 1.1.0. Affected is the function system of the file /backup.pl. The manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
EasyNAS | CVE List | 1.1.0 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBEasyNas 1.1.0 - OS Command InjectionExploitDB exploitby Ivan SpiridonovNot analyzed1 file
Repository PoCs
GitHubxbz0n/CVE-2023-0830Repository PoCby xbz0nStars: 1Not analyzed2 files
References
7github.comexploit
https://github.com/xbz0n/CVE-2023-0830 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-0830 VDB-220950 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.220950 VDB-220950 | EasyNAS backup.pl system os command injectionvdb entryTechnical description
https://vuldb.com/?id.220950 Submit #86683 | EasyNAS 1.1.0 - Authenticated OS Command InjectionThird-party advisory
https://vuldb.com/?submit.86683 exploit-db.comexploit
https://www.exploit-db.com/exploits/51266