CVE-2023-22581

White Rabbit Switch contains a vulnerability which makes it possible for an attacker to perform system commands under the context of the web application (the default installation makes the webserver run as the root user).
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:home.cern:white_rabbit_switch_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:home.cern:white_rabbit_switch:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:45

Type Values Removed Values Added
References () https://csirt.divd.nl/CVE-2023-22581/ - Broken Link () https://csirt.divd.nl/CVE-2023-22581/ - Broken Link
References () https://csirt.divd.nl/DIVD-2022-00068/ - Broken Link () https://csirt.divd.nl/DIVD-2022-00068/ - Broken Link

02 May 2023, 19:16

Type Values Removed Values Added
CPE cpe:2.3:o:home.cern:white_rabbit_switch_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:home.cern:white_rabbit_switch:-:*:*:*:*:*:*:*
References
  • (MISC) https://vuldb.com/?id.227269 - Third Party Advisory
References (MISC) https://csirt.divd.nl/DIVD-2022-00068/ - (MISC) https://csirt.divd.nl/DIVD-2022-00068/ - Broken Link
References (MISC) https://csirt.divd.nl/CVE-2023-22581/ - (MISC) https://csirt.divd.nl/CVE-2023-22581/ - Broken Link
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE NVD-CWE-noinfo

24 Apr 2023, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-24 09:15

Updated : 2024-11-21 07:45


NVD link : CVE-2023-22581

Mitre link : CVE-2023-22581

CVE.ORG link : CVE-2023-22581


JSON object : View

Products Affected

home.cern

  • white_rabbit_switch
  • white_rabbit_switch_firmware
CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo