Record summary

CVE-2023-49897 has a selected CVSS score of 8.8 (high). CISA lists CVE-2023-49897 in KEV.

Description

An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Dec 21, 2023 · CISA
VulnCheck KEV
Listed · Dec 6, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 20, 2023 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE List2.0.9 and earlieraffected
CVE List2.0.9 and earlieraffected

References

6