Record summary

CVE-2023-41109 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALSmartNode SN200 Analog Telephone Adapter (ATA) & VoIP Gateway - Command InjectionCVSS 9.8

The SmartNode SN200 Analog Telephone Adapter (ATA) & VoIP Gateway is vulnerable to command injection.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the affected device.

Remediation

Apply the latest firmware update provided by the vendor to mitigate this vulnerability.

WeaknessesCWE-78
Authorsprincechaddha
Template tagscvecve2023smartnodevoippattonvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:h:patton:smartnode_sn200:-:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5