jvn.jp
https://jvn.jp/en/vu/JVNVU92152057 CVE-2023-49897
HIGHCISA KEV
FXC AE1021, AE1021PE OS Command Injection Vulnerability
Record summary
CVE-2023-49897 has a selected CVSS score of 8.8 (high). CISA lists CVE-2023-49897 in KEV.
Description
An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Dec 21, 2023 · CISA
- VulnCheck KEV
- Listed · Dec 6, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 20, 2023 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
AE1021, AE1021PEBrowse FXC / AE1021, AE1021PE | CISA | Version data not supplied | |
AE1021Browse FXC Inc. / AE1021 | CVE List | 2.0.9 and earlier | affected |
AE1021PEBrowse FXC Inc. / AE1021PE | CVE List | 2.0.9 and earlier | affected |
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-49897 akamai.com
https://www.akamai.com/blog/security-research/zero-day-vulnerability-spreading-mirai-patched cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-49897 cisa.gov
https://www.cisa.gov/news-events/ics-advisories/icsa-23-355-01 fxc.jp
https://www.fxc.jp/news/20231206