CVE-2023-38317: OS Command Injection
Published Jan 26, 2024
·Updated
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.
Affected Software
1 affected component
OpenNDS openNDS<10.1.3
Event History
Jan 26, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-38317?
CVE-2023-38317 is considered a critical vulnerability due to its ability to allow arbitrary OS command execution.
2
How do I fix CVE-2023-38317?
To fix CVE-2023-38317, you should upgrade OpenNDS to version 10.1.3 or later.
3
Who is affected by CVE-2023-38317?
CVE-2023-38317 affects all versions of OpenNDS prior to 10.1.3.
4
Can CVE-2023-38317 be exploited remotely?
CVE-2023-38317 can potentially be exploited by attackers with direct or indirect access to the configuration file.
5
What are the consequences of CVE-2023-38317?
The consequences of CVE-2023-38317 include the possibility of an attacker executing arbitrary commands on the operating system.