packetstormsecurity.com
http://packetstormsecurity.com/files/175945/SmartNode-SN200-3.21.2-23021-OS-Command-Injection.html CVE-2023-41109
CRITICALNuclei
patton smartnode_sn200_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2023-41109 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 22, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
smartnode_sn200_firmwareBrowse patton / smartnode_sn200_firmware | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALSmartNode SN200 Analog Telephone Adapter (ATA) & VoIP Gateway - Command InjectionCVSS 9.8
The SmartNode SN200 Analog Telephone Adapter (ATA) & VoIP Gateway is vulnerable to command injection.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the affected device.
Remediation
Apply the latest firmware update provided by the vendor to mitigate this vulnerability.
WeaknessesCWE-78
Authorsprincechaddha
Template tagscvecve2023smartnodevoippattonvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:h:patton:smartnode_sn200:-:*:*:*:*:*:*:*
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2023-019.txt https://nvd.nist.gov/vuln/detail/CVE-2023-41109 http://packetstormsecurity.com/files/175945/SmartNode-SN200-3.21.2-23021-OS-Command-Injection.html http://seclists.org/fulldisclosure/2023/Nov/12 https://www.syss.de/
Source: ProjectDiscovery
References
520231127 [SYSS-2023-019] SmartNode SN200 - Unauthenticated OS Command Injectionmailing list
http://seclists.org/fulldisclosure/2023/Nov/12 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-41109 syss.de
https://www.syss.de/ syss.de
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2023-019.txt