CVE-2023-43322

HIGH

ZPE Systems, Inc Nodegrid OS <5.10.4 - Command Injection

Title source: llm
STIX 2.1

Description

ZPE Systems, Inc Nodegrid OS v5.0.0 to v5.0.17, v5.2.0 to v5.2.19, v5.4.0 to v5.4.16, v5.6.0 to v5.6.13, v5.8.0 to v5.8.10, and v5.10.0 to v5.10.3 was discovered to contain a command injection vulnerability via the endpoint /v1/system/toolkit/files/.

Scores

CVSS v3 8.8
EPSS 0.0109
EPSS Percentile 61.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
zpesystems/nodegrid_os 5.0.0 - 5.0.18
Published Oct 28, 2023
Tracked Since Feb 18, 2026