CVE-2023-43321: Malicious File Upload
Published Oct 4, 2023
·Updated
File Upload vulnerability in Digital China Networks DCFW-1800-SDC v.3.0 allows an authenticated attacker to execute arbitrary code via the wget function in the /sbin/cloudadmin.sh component.
Affected Software
2 affected components
Dcnetworks Dcfw-1800-sdc Firmware=3.0
Dcnetworks Dcfw-1800-sdc
Event History
Oct 4, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-43321.
2
How severe is CVE-2023-43321?
CVE-2023-43321 has a severity value of 8.8, which is considered high.
3
What can an attacker do with CVE-2023-43321?
An authenticated attacker can execute arbitrary code using the wget function in the /sbin/cloudadmin.sh component.
4
Which software versions are affected by CVE-2023-43321?
Digital China Networks DCFW-1800-SDC v.3.0 is affected by CVE-2023-43321.
5
How can CVE-2023-43321 be fixed?
There is no known fix or patch available for CVE-2023-43321 at the moment. It is recommended to monitor vendor advisories for updates or mitigation guidance.