CVE-2023-38317
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 26, 2024
Updated: Feb 2, 2024
CWE ID 78
Summary
CVE-2023-38317 is a vulnerability affecting OpenNDS versions prior to 10.1.3. This issue arises from the software's failure to sanitize the network interface name entry in its configuration file. Consequently, attackers with access to this file can exploit the flaw to execute arbitrary OS commands, potentially leading to significant security risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share