CVE-2023-42495: Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Published Dec 13, 2023
·Updated
Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Affected Software
1 affected component
Dasannetworks W-web>=1.22<=1.27
Event History
Dec 13, 2023
CVE Published
12:48 PM
Data Sourced
12:48 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-42495?
CVE-2023-42495 has a high severity level due to the potential for OS command injection.
2
How do I fix CVE-2023-42495?
To fix CVE-2023-42495, update Dasan Networks W-Web to version 1.28 or later.
3
What software versions are affected by CVE-2023-42495?
CVE-2023-42495 affects Dasan Networks W-Web versions 1.22 to 1.27 inclusive.
4
What type of vulnerability is CVE-2023-42495?
CVE-2023-42495 is classified as an OS command injection vulnerability.
5
Can CVE-2023-42495 be exploited remotely?
Yes, CVE-2023-42495 can potentially be exploited remotely if the vulnerable software is accessible.