CVE-2023-45467: OS Command Injection
Published Oct 13, 2023
·Updated
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ntpServIP parameter in the Time Settings.
Affected Software
2 affected components
netis-systems N3m Firmware=1.0.1.865
netis-systems N3m=v2
Event History
Oct 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-45467?
CVE-2023-45467 is a command injection vulnerability found in Netis N3Mv2-V1.0.1.865 through the ntpServIP parameter in the Time Settings.
2
How severe is CVE-2023-45467?
CVE-2023-45467 is categorized as a critical vulnerability with a severity rating of 9.8.
3
How does CVE-2023-45467 affect Netis N3Mv2 firmware version 1.0.1.865?
Netis N3Mv2 firmware version 1.0.1.865 is affected by CVE-2023-45467 and is vulnerable to command injection via the ntpServIP parameter in the Time Settings.
4
Is Netis N3Mv2 hardware version 2 affected by CVE-2023-45467?
No, Netis N3Mv2 hardware version 2 is not affected by CVE-2023-45467.
5
How can I fix the command injection vulnerability in Netis N3Mv2 firmware version 1.0.1.865?
To fix the command injection vulnerability in Netis N3Mv2 firmware version 1.0.1.865, it is recommended to apply the latest firmware update provided by Netis-systems.