CVE-2023-50993: Command Injection
Ruijie WS6008 v1.x v2.x ACRGOS11.9(6)W3B2G2C6-0110221911 and WS6108 v1.x ACRGOS11.9(6)W3B2G2C6-0110221911 was discovered to contain a command injection vulnerability via the function downFiles.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50993?
CVE-2023-50993 is rated as a high severity vulnerability due to its potential for command injection.
How do I fix CVE-2023-50993?
To remediate CVE-2023-50993, update the Ruijie WS6008 and WS6108 firmware to a version that does not include this vulnerability.
What types of devices are affected by CVE-2023-50993?
CVE-2023-50993 affects the Ruijie WS6008 and WS6108 devices running the specified firmware version.
Can CVE-2023-50993 be exploited remotely?
Yes, CVE-2023-50993 can be exploited remotely, allowing an attacker to execute commands on the affected devices.
What is the cause of CVE-2023-50993?
CVE-2023-50993 is caused by improper validation of input data in the downFiles function, leading to command injection.