CVE-2023-6357

HIGH

File System Libraries - Command Injection

Title source: llm
STIX 2.1

Description

A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0096
EPSS Percentile 56.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (11)
codesys/control_for_beaglebone_sl < 4.11.0.0
codesys/control_for_empc-a\/imx6 < 4.11.0.0
codesys/control_for_iot2000_sl < 4.11.0.0
codesys/control_for_linux_arm_sl < 4.11.0.0
codesys/control_for_linux_sl < 4.11.0.0
codesys/control_for_pfc100_sl < 4.11.0.0
codesys/control_for_pfc200_sl < 4.11.0.0
codesys/control_for_plcnext_sl < 4.11.0.0
codesys/control_for_raspberry_pi_sl < 4.11.0.0
codesys/control_for_wago_touch_panels_600_sl < 4.11.0.0
... and 1 more
Published Dec 05, 2023
Tracked Since Feb 18, 2026