CVE-2023-22581

CRITICAL

White Rabbit Switch < 6.0.1 - OS Command Injection

Title source: llm
STIX 2.1

Description

White Rabbit Switch contains a vulnerability which makes it possible for an attacker to perform system commands under the context of the web application (the default installation makes the webserver run as the root user).

References (3)

Core 3
Core References
Third Party Advisory
https://vuldb.com/?id.227269
Broken Link third-party-advisory
https://csirt.divd.nl/CVE-2023-22581/
Broken Link third-party-advisory
https://csirt.divd.nl/DIVD-2022-00068/

Scores

CVSS v3 9.8
EPSS 0.0069
EPSS Percentile 48.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-20
Status published
Products (1)
home.cern/white_rabbit_switch_firmware < 6.0.1
Published Apr 24, 2023
Tracked Since Feb 18, 2026