CVE-2023-38318: OS Command Injection
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38318?
CVE-2023-38318 is classified as a high-severity vulnerability due to the potential for arbitrary OS command execution.
How do I fix CVE-2023-38318?
To fix CVE-2023-38318, upgrade OpenNDS to version 10.1.3 or later, which addresses this vulnerability.
What type of vulnerability is CVE-2023-38318?
CVE-2023-38318 is a command injection vulnerability caused by improper sanitization of the gateway FQDN entry in the configuration file.
Who is affected by CVE-2023-38318?
CVE-2023-38318 affects all versions of OpenNDS prior to version 10.1.3.
Can CVE-2023-38318 be exploited remotely?
Yes, CVE-2023-38318 can be exploited by attackers with either direct or indirect access to the configuration file.