First published: Fri Nov 17 2023(Updated: )
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.
Credit: psirt-info@cyber.jp.nec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nec Expresscluster X | =1.0 | |
Nec Expresscluster X | =1.0 | |
Nec Expresscluster X | =2.0 | |
Nec Expresscluster X | =2.0 | |
Nec Expresscluster X | =2.1 | |
Nec Expresscluster X | =2.1 | |
Nec Expresscluster X | =3.0 | |
Nec Expresscluster X | =3.0 | |
Nec Expresscluster X | =3.1 | |
Nec Expresscluster X | =3.1 | |
Nec Expresscluster X | =3.2 | |
Nec Expresscluster X | =3.2 | |
Nec Expresscluster X | =3.3 | |
Nec Expresscluster X | =3.3 | |
Nec Expresscluster X | =4.0 | |
Nec Expresscluster X | =4.0 | |
Nec Expresscluster X | =4.1 | |
Nec Expresscluster X | =4.1 | |
Nec Expresscluster X | =4.2 | |
Nec Expresscluster X | =4.2 | |
Nec Expresscluster X | =4.3 | |
Nec Expresscluster X | =4.3 | |
Nec Expresscluster X | =5.0 | |
Nec Expresscluster X | =5.0 | |
Nec Expresscluster X | =5.1 | |
Nec Expresscluster X | =5.1 | |
Nec Expresscluster X Singleserversafe | =1.0 | |
Nec Expresscluster X Singleserversafe | =1.0 | |
Nec Expresscluster X Singleserversafe | =2.0 | |
Nec Expresscluster X Singleserversafe | =2.0 | |
Nec Expresscluster X Singleserversafe | =2.1 | |
Nec Expresscluster X Singleserversafe | =2.1 | |
Nec Expresscluster X Singleserversafe | =3.0 | |
Nec Expresscluster X Singleserversafe | =3.0 | |
Nec Expresscluster X Singleserversafe | =3.1 | |
Nec Expresscluster X Singleserversafe | =3.1 | |
Nec Expresscluster X Singleserversafe | =3.2 | |
Nec Expresscluster X Singleserversafe | =3.2 | |
Nec Expresscluster X Singleserversafe | =3.3 | |
Nec Expresscluster X Singleserversafe | =3.3 | |
Nec Expresscluster X Singleserversafe | =4.0 | |
Nec Expresscluster X Singleserversafe | =4.0 | |
Nec Expresscluster X Singleserversafe | =4.1 | |
Nec Expresscluster X Singleserversafe | =4.1 | |
Nec Expresscluster X Singleserversafe | =4.2 | |
Nec Expresscluster X Singleserversafe | =4.2 | |
Nec Expresscluster X Singleserversafe | =4.3 | |
Nec Expresscluster X Singleserversafe | =4.3 | |
Nec Expresscluster X Singleserversafe | =5.0 | |
Nec Expresscluster X Singleserversafe | =5.0 | |
Nec Expresscluster X Singleserversafe | =5.1 | |
Nec Expresscluster X Singleserversafe | =5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39546 is a vulnerability in CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, where an attacker can log in to the product and execute an arbitrary command.
The severity of CVE-2023-39546 is rated as high, with a CVSS score of 8.8.
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, along with specific versions of NEC Expresscluster X and NEC Expresscluster X Singleserversafe, are affected by CVE-2023-39546.
An attacker can exploit CVE-2023-39546 by logging in to the affected product and executing arbitrary commands.
Yes, NEC has released a security advisory with details on how to mitigate the CVE-2023-39546 vulnerability. Please refer to the official NEC website for the fix.