CVE-2023-41921

CRITICAL

Firmware Modification - Code Injection

Title source: llm
STIX 2.1

Description

A vulnerability allows attackers to download source code or an executable from a remote location and execute the code without sufficiently verifying the origin and integrity of the code. This vulnerability can allow attackers to modify the firmware before uploading it to the system, thus achieving the modification of the target’s integrity to achieve an insecure state.

Scores

CVSS v3 9.8
EPSS 0.0013
EPSS Percentile 32.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-494
Status published
Products (1)
Kiloview/P1/P2 All - 4.8.2605
Published Jul 02, 2024
Tracked Since Feb 18, 2026