CVE-2023-52163: Digiever DS-2105 Pro Missing Authorization Vulnerability
Digiever DS-2105 Pro 3.1.0.71-11 devices allow timetzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Other sources
Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via timetzsetup.cgi.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Digiever DS-2105 Profrom your environment.Discontinue use of the product or uninstall the device if mitigations are unavailable.
- Compensating control
Apply mitigations per vendor instructions and follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52163?
CVE-2023-52163 has a high severity due to its potential for command injection on affected devices.
How do I fix CVE-2023-52163?
There is no fix for CVE-2023-52163 as it affects unsupported Digiever DS-2105 Pro devices.
What types of devices are affected by CVE-2023-52163?
CVE-2023-52163 specifically affects Digiever DS-2105 Pro devices running firmware version 3.1.0.71-11.
Can CVE-2023-52163 be exploited remotely?
Yes, CVE-2023-52163 can be exploited remotely if the device is accessible over the internet.
What are the potential impacts of CVE-2023-52163?
Exploitation of CVE-2023-52163 can lead to unauthorized command execution on the affected device.