CVE-2023-49897: FXC AE1021, AE1021PE OS Command Injection Vulnerability
An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Other sources
FXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of the affected product (FXC AE1021 and FXC AE1021PE) if vendor mitigations are unavailable.
- Compensating control
Restrict network access to the management interfaces of FXC AE1021 and FXC AE1021PE to trusted administrative IPs (via firewall/ACL or isolated management network) to reduce exposure to remote authenticated attackers.
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49897?
CVE-2023-49897 is a critical severity OS command injection vulnerability.
How do I fix CVE-2023-49897?
To fix CVE-2023-49897, update the firmware of AE1021 and AE1021PE devices to version 2.0.10 or later.
Who is affected by CVE-2023-49897?
CVE-2023-49897 affects users of FXC AE1021 and AE1021PE firmware versions 2.0.9 and earlier.
What can an attacker do with CVE-2023-49897?
An attacker exploiting CVE-2023-49897 can execute arbitrary OS commands if they gain login access to the device.
Is CVE-2023-49897 specific to certain firmware versions?
Yes, CVE-2023-49897 is specifically present in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier.