CVE-2023-25911: Authenticated OS Command Injection in Danfoss AK-EM100
Published Jun 11, 2023
·Updated
The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web application parameters.
Other sources
The Danfoss AK-EM100 web applications allow for OS command injection through the web application parameters.
Affected Software
4 affected components
All of the following
Danfoss Ak-em100 Firmware<2.2.0.12
Danfoss AK-EM100
Danfoss Ak-em100 Firmware<2.2.0.12
Danfoss AK-EM100
Event History
Jun 11, 2023
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-25911?
The severity of CVE-2023-25911 is critical.
2
What is the vulnerability description of CVE-2023-25911?
The Danfoss AK-EM100 web applications allow for OS command injection through the web application parameters.
3
Which software versions are affected by CVE-2023-25911?
The Danfoss AK-EM100 firmware versions up to and excluding 2.2.0.12 are affected by CVE-2023-25911.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-25911?
The CWE IDs associated with CVE-2023-25911 are CWE-77 and CWE-78.
5
Where can I find more information about CVE-2023-25911?
You can find more information about CVE-2023-25911 at the following references: [1] [2]