CVE-2023-23912

A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with their DHCPv6 prefix delegation set to dhcpv6-stateless or dhcpv6-stateful, allows a malicious actor directly connected to the WAN interface of an affected device to create a remote code execution vulnerability.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ui:usg_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:usg:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ui:usg-pro-4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:usg-pro-4:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:ui:er-10x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ui:er-10x_firmware:2.0.9:-:*:*:*:*:*:*
cpe:2.3:o:ui:er-10x_firmware:2.0.9:hotfix2:*:*:*:*:*:*
cpe:2.3:o:ui:er-10x_firmware:2.0.9:hotfix4:*:*:*:*:*:*
cpe:2.3:o:ui:er-10x_firmware:2.0.9:hotfix5:*:*:*:*:*:*
cpe:2.3:h:ui:er-10x:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:ui:er-12_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ui:er-12_firmware:2.0.9:-:*:*:*:*:*:*
cpe:2.3:o:ui:er-12_firmware:2.0.9:hotfix2:*:*:*:*:*:*
cpe:2.3:o:ui:er-12_firmware:2.0.9:hotfix4:*:*:*:*:*:*
cpe:2.3:o:ui:er-12_firmware:2.0.9:hotfix5:*:*:*:*:*:*
cpe:2.3:h:ui:er-12:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
OR cpe:2.3:o:ui:er-12p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ui:er-12p_firmware:2.0.9:-:*:*:*:*:*:*
cpe:2.3:o:ui:er-12p_firmware:2.0.9:hotfix2:*:*:*:*:*:*
cpe:2.3:o:ui:er-12p_firmware:2.0.9:hotfix4:*:*:*:*:*:*
cpe:2.3:o:ui:er-12p_firmware:2.0.9:hotfix5:*:*:*:*:*:*
cpe:2.3:h:ui:er-12p:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
OR cpe:2.3:o:ui:er-4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ui:er-4_firmware:2.0.9:-:*:*:*:*:*:*
cpe:2.3:o:ui:er-4_firmware:2.0.9:hotfix2:*:*:*:*:*:*
cpe:2.3:o:ui:er-4_firmware:2.0.9:hotfix4:*:*:*:*:*:*
cpe:2.3:o:ui:er-4_firmware:2.0.9:hotfix5:*:*:*:*:*:*
cpe:2.3:h:ui:er-4:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
OR cpe:2.3:o:ui:er-6p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ui:er-6p_firmware:2.0.9:-:*:*:*:*:*:*
cpe:2.3:o:ui:er-6p_firmware:2.0.9:hotfix2:*:*:*:*:*:*
cpe:2.3:o:ui:er-6p_firmware:2.0.9:hotfix4:*:*:*:*:*:*
cpe:2.3:o:ui:er-6p_firmware:2.0.9:hotfix5:*:*:*:*:*:*
cpe:2.3:h:ui:er-6p:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
OR cpe:2.3:o:ui:er-8-xg_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ui:er-8-xg_firmware:2.0.9:-:*:*:*:*:*:*
cpe:2.3:o:ui:er-8-xg_firmware:2.0.9:hotfix2:*:*:*:*:*:*
cpe:2.3:o:ui:er-8-xg_firmware:2.0.9:hotfix4:*:*:*:*:*:*
cpe:2.3:o:ui:er-8-xg_firmware:2.0.9:hotfix5:*:*:*:*:*:*
cpe:2.3:h:ui:er-8-xg:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
OR cpe:2.3:o:ui:er-x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ui:er-x_firmware:2.0.9:-:*:*:*:*:*:*
cpe:2.3:o:ui:er-x_firmware:2.0.9:hotfix2:*:*:*:*:*:*
cpe:2.3:o:ui:er-x_firmware:2.0.9:hotfix4:*:*:*:*:*:*
cpe:2.3:o:ui:er-x_firmware:2.0.9:hotfix5:*:*:*:*:*:*
cpe:2.3:h:ui:er-x:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
OR cpe:2.3:o:ui:er-x-sfp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ui:er-x-sfp_firmware:2.0.9:-:*:*:*:*:*:*
cpe:2.3:o:ui:er-x-sfp_firmware:2.0.9:hotfix2:*:*:*:*:*:*
cpe:2.3:o:ui:er-x-sfp_firmware:2.0.9:hotfix4:*:*:*:*:*:*
cpe:2.3:o:ui:er-x-sfp_firmware:2.0.9:hotfix5:*:*:*:*:*:*
cpe:2.3:h:ui:er-x-sfp:-:*:*:*:*:*:*:*

History

17 Feb 2023, 20:04

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-09 20:15

Updated : 2024-02-04 23:14


NVD link : CVE-2023-23912

Mitre link : CVE-2023-23912

CVE.ORG link : CVE-2023-23912


JSON object : View

Products Affected

ui

  • er-6p_firmware
  • er-8-xg
  • er-12_firmware
  • er-4
  • er-10x
  • er-12p_firmware
  • er-8-xg_firmware
  • er-x-sfp_firmware
  • er-12
  • er-10x_firmware
  • usg
  • er-x
  • er-6p
  • usg_firmware
  • er-12p
  • er-x_firmware
  • er-x-sfp
  • usg-pro-4
  • er-4_firmware
  • usg-pro-4_firmware
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-75

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)