CVE-2023-42336

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Sep 16, 2023
Updated: Sep 20, 2023
CWE ID 798

Summary

CVE-2023-42336 is a vulnerability affecting NETIS SYSTEMS WF2409Ev4 version 1.0.1.705. An attacker can exploit this issue by manipulating the password parameter in the /etc/shadow.sample component, allowing them to execute arbitrary code and gain access to sensitive information remotely. This vulnerability poses a significant risk to systems running this version of WF2409Ev4 and should be addressed promptly by applying the necessary patches or updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share