CVE-2023-6071: Command Injection
An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator to execute arbitrary code as root on the ESM. This is possible as the input isn't correctly sanitized when adding a new data source.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-6071?
CVE-2023-6071 is a vulnerability that allows a remote administrator to execute arbitrary code as root on the ESM.
How does CVE-2023-6071 occur?
CVE-2023-6071 occurs due to an improper neutralization of special elements used in a command vulnerability in ESM prior to version 11.6.9.
How severe is CVE-2023-6071?
CVE-2023-6071 has a severity rating of 8.4 (high).
How can I fix CVE-2023-6071?
To fix CVE-2023-6071, update your Trellix Enterprise Security Manager (ESM) to version 11.6.9 or later.
Where can I find more information about CVE-2023-6071?
You can find more information about CVE-2023-6071 at the following link: https://kcm.trellix.com/corporate/index?page=content&id=SB10413