Record summary

CVE-2023-45852 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 4, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 17, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALViessmann Vitogate 300 - Remote Code ExecutionCVSS 9.8

In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method.

Impact

Unauthenticated attackers can execute arbitrary commands with elevated privileges through shell metacharacters in the ipaddr parameter, potentially compromising the heating control gateway and accessing building management systems.

Remediation

Update Viessmann Vitogate 300 firmware to a version newer than 2.1.3.0 that properly sanitizes the ipaddr parameter and prevents command injection through the JSON API.

WeaknessesCWE-77
Authorsiamnoooob, rootxharsh, pdresearch
Template tagscve2023cvercevitogateviessmannvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:viessmann:vitogate_300_firmware:*:*:*:*:*:*:*:*
Shodan: title:"Vitogate 300"
Shodan: http.title:"vitogate 300"
FOFA: title="Vitogate 300"
FOFA: title="vitogate 300"
Google: intitle:"vitogate 300"

Source: ProjectDiscovery

References

3