CVE-2023-29804: OS Command Injection
Published Apr 14, 2023
·Updated
WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the syssmbpwdmod function.
Affected Software
8 affected components
Iodata Wfs-sr03w Firmware=1.03
Iodata Wfs-sr03w
Iodata Wfs-sr03k Firmware=1.03
Iodata Wfs-sr03k
All of the following
Iodata Wfs-sr03w Firmware=1.03
Iodata Wfs-sr03w
All of the following
Iodata Wfs-sr03k Firmware=1.03
Iodata Wfs-sr03k
Event History
Apr 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-29804?
CVE-2023-29804 is a command injection vulnerability found in WFS-SR03 v1.0.3.
2
How severe is CVE-2023-29804?
CVE-2023-29804 has a severity score of 8.8, which is considered high.
3
Which software versions are affected by CVE-2023-29804?
CVE-2023-29804 affects Iodata Wfs-sr03w Firmware version 1.03 and Iodata Wfs-sr03k Firmware version 1.03.
4
How can I fix CVE-2023-29804?
To fix CVE-2023-29804, it is recommended to update the affected software to a patched version provided by Iodata.
5
Where can I find more information about CVE-2023-29804?
More information about CVE-2023-29804 can be found at the following link: [https://sore-pail-31b.notion.site/command-injection-WFS-SR03-7cddf0ac85e54f8ba81d9b26b00ca5cd]