CVE-2023-37292: HGiga iSherlock - Command Injection
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in HGiga iSherlock 4.5 (iSherlock-user modules), HGiga iSherlock 5.5 (iSherlock-user modules) allows OS Command Injection.This issue affects iSherlock 4.5: before iSherlock-user-4.5-174; iSherlock 5.5: before iSherlock-user-5.5-174.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HGiga iSherlock iSherlock-user moduleto a version that resolves this vulnerability.Fixed in 5.5-174Patch MSR55 - Upgrade
Upgrade
HGiga iSherlock iSherlock-user moduleto a version that resolves this vulnerability.Fixed in 4.5-174Patch MSR45
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37292?
The severity of CVE-2023-37292 is classified as high due to the potential for OS Command Injection.
How do I fix CVE-2023-37292?
To fix CVE-2023-37292, update the iSherlock software to versions 4.5.174 or higher, or 5.5.174 or higher.
What systems are affected by CVE-2023-37292?
CVE-2023-37292 affects HGiga iSherlock versions 4.5 up to 4.5.174 and versions 5.5 up to 5.5.174.
What is OS Command Injection in the context of CVE-2023-37292?
OS Command Injection in CVE-2023-37292 refers to the vulnerability that allows attackers to execute arbitrary commands on the host operating system.
What can happen if CVE-2023-37292 is exploited?
If exploited, CVE-2023-37292 can allow an attacker to gain unauthorized access and control over the affected system.