CVE-2023-3313: OS Command Injection
An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed an unauthorized user to execute system command injection for the purpose of privilege escalation or to execute arbitrary commands.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3313?
CVE-2023-3313 is an OS command injection vulnerability in the ESM certificate API.
How does CVE-2023-3313 impact my system?
CVE-2023-3313 allows an unauthorized user to execute system command injection, potentially leading to privilege escalation or execution of arbitrary commands.
What software versions are affected by CVE-2023-3313?
Trellix Enterprise Security Manager versions up to and excluding 11.6.7 are affected by CVE-2023-3313.
What is the severity of CVE-2023-3313?
CVE-2023-3313 has a severity score of 7.8, indicating a high severity.
How can I fix CVE-2023-3313?
To fix CVE-2023-3313, it is recommended to update Trellix Enterprise Security Manager to version 11.6.7 or later.
Where can I find more information about CVE-2023-3313?
More information about CVE-2023-3313 can be found at: https://kcm.trellix.com/corporate/index?page=content&id=SB10403