nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-3267 CVE-2023-3267
CRITICAL
Record summary
CVE-2023-3267 has a selected CVSS score of 9.1 (critical).
Description
When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An authenticated attacker can leverage this vulnerability to execute arbitrary code with system-level access to the CyberPower PowerPanel Enterprise server.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 9, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PowerPanel EnterpriseBrowse CyberPower / PowerPanel EnterpriseDefault status: unaffected | CVE List | v2.6.0 | affected |
References
2trellix.com
https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html