First published: Wed Dec 06 2023(Updated: )
An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
FXC AE1021PE firmware | ||
All of | ||
FXC AE1021PE firmware | <2.0.10 | |
FXC AE1021 firmware | ||
All of | ||
FXC AE1021PE firmware | <2.0.10 | |
FXC AE1021PE firmware |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49897 is a critical severity OS command injection vulnerability.
To fix CVE-2023-49897, update the firmware of AE1021 and AE1021PE devices to version 2.0.10 or later.
CVE-2023-49897 affects users of FXC AE1021 and AE1021PE firmware versions 2.0.9 and earlier.
An attacker exploiting CVE-2023-49897 can execute arbitrary OS commands if they gain login access to the device.
Yes, CVE-2023-49897 is specifically present in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier.