CVE-2023-43959: OS Command Injection
Published Oct 17, 2023
·Updated
An issue in YeaLinkSIP-T19P-E2 v.53.84.0.15 allows a remote privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.
Affected Software
2 affected components
Yealink Sip-t19p-e2 Firmware=53.84.0.15
Yealink SIP-T19P-E2
Event History
Oct 17, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
02:15 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-43959.
2
What is the severity of CVE-2023-43959?
CVE-2023-43959 has a severity of 8.8 (high).
3
What is the affected software for CVE-2023-43959?
The affected software for CVE-2023-43959 is Yealink Sip-t19p-e2 Firmware v.53.84.0.15.
4
How does CVE-2023-43959 allow an attacker to execute arbitrary code?
CVE-2023-43959 allows a remote privileged attacker to execute arbitrary code via a crafted request to the ping function of the diagnostic component in Yealink SIP-T19P-E2 v.53.84.0.15 firmware.
5
How can I fix CVE-2023-43959?
To fix CVE-2023-43959, it is recommended to update the Yealink SIP-T19P-E2 firmware to a version that addresses the issue.