Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2023-38198
acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.002
EPSS Ranking
41.9%
CVSS Severity
CVSS v3 Score
9.8
References
http://www.openwall.com/lists/oss-security/2023/07/13/1
https://github.com/acmesh-official/acme.sh/issues/4659
https://github.com/acmesh-official/acme.sh/releases/tag/3.0.6
https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/heXVr8o83Ys
https://news.ycombinator.com/item?id=36252310
https://news.ycombinator.com/item?id=36254093
https://www.reddit.com/r/netsec/comments/144ygg7/acmesh_runs_arbitrary_commands_from_a_remote/
http://www.openwall.com/lists/oss-security/2023/07/13/1
https://github.com/acmesh-official/acme.sh/issues/4659
https://github.com/acmesh-official/acme.sh/releases/tag/3.0.6
https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/heXVr8o83Ys
https://news.ycombinator.com/item?id=36252310
https://news.ycombinator.com/item?id=36254093
https://www.reddit.com/r/netsec/comments/144ygg7/acmesh_runs_arbitrary_commands_from_a_remote/
Products affected by CVE-2023-38198
Acme.sh Project
»
Acme.sh
»
Version:
1.2.2
cpe:2.3:a:acme.sh_project:acme.sh:1.2.2
Acme.sh Project
»
Acme.sh
»
Version:
1.2.3
cpe:2.3:a:acme.sh_project:acme.sh:1.2.3
Acme.sh Project
»
Acme.sh
»
Version:
2.0.2
cpe:2.3:a:acme.sh_project:acme.sh:2.0.2
Acme.sh Project
»
Acme.sh
»
Version:
2.2.9
cpe:2.3:a:acme.sh_project:acme.sh:2.2.9
Acme.sh Project
»
Acme.sh
»
Version:
2.3.0
cpe:2.3:a:acme.sh_project:acme.sh:2.3.0
Acme.sh Project
»
Acme.sh
»
Version:
2.5.2
cpe:2.3:a:acme.sh_project:acme.sh:2.5.2
Acme.sh Project
»
Acme.sh
»
Version:
2.6.0
cpe:2.3:a:acme.sh_project:acme.sh:2.6.0
Acme.sh Project
»
Acme.sh
»
Version:
2.6.4
cpe:2.3:a:acme.sh_project:acme.sh:2.6.4
Acme.sh Project
»
Acme.sh
»
Version:
2.6.5
cpe:2.3:a:acme.sh_project:acme.sh:2.6.5
Acme.sh Project
»
Acme.sh
»
Version:
2.6.6
cpe:2.3:a:acme.sh_project:acme.sh:2.6.6
Acme.sh Project
»
Acme.sh
»
Version:
2.6.8
cpe:2.3:a:acme.sh_project:acme.sh:2.6.8
Acme.sh Project
»
Acme.sh
»
Version:
2.6.9
cpe:2.3:a:acme.sh_project:acme.sh:2.6.9
Acme.sh Project
»
Acme.sh
»
Version:
2.7.1
cpe:2.3:a:acme.sh_project:acme.sh:2.7.1
Acme.sh Project
»
Acme.sh
»
Version:
2.7.2
cpe:2.3:a:acme.sh_project:acme.sh:2.7.2
Acme.sh Project
»
Acme.sh
»
Version:
2.7.3
cpe:2.3:a:acme.sh_project:acme.sh:2.7.3
Acme.sh Project
»
Acme.sh
»
Version:
2.7.4
cpe:2.3:a:acme.sh_project:acme.sh:2.7.4
Acme.sh Project
»
Acme.sh
»
Version:
2.7.5
cpe:2.3:a:acme.sh_project:acme.sh:2.7.5
Acme.sh Project
»
Acme.sh
»
Version:
2.7.6
cpe:2.3:a:acme.sh_project:acme.sh:2.7.6
Acme.sh Project
»
Acme.sh
»
Version:
2.7.7
cpe:2.3:a:acme.sh_project:acme.sh:2.7.7
Acme.sh Project
»
Acme.sh
»
Version:
2.7.8
cpe:2.3:a:acme.sh_project:acme.sh:2.7.8
Acme.sh Project
»
Acme.sh
»
Version:
2.7.9
cpe:2.3:a:acme.sh_project:acme.sh:2.7.9
Acme.sh Project
»
Acme.sh
»
Version:
2.8.0
cpe:2.3:a:acme.sh_project:acme.sh:2.8.0
Acme.sh Project
»
Acme.sh
»
Version:
2.8.1
cpe:2.3:a:acme.sh_project:acme.sh:2.8.1
Acme.sh Project
»
Acme.sh
»
Version:
2.8.2
cpe:2.3:a:acme.sh_project:acme.sh:2.8.2
Acme.sh Project
»
Acme.sh
»
Version:
2.8.3
cpe:2.3:a:acme.sh_project:acme.sh:2.8.3
Acme.sh Project
»
Acme.sh
»
Version:
2.8.4
cpe:2.3:a:acme.sh_project:acme.sh:2.8.4
Acme.sh Project
»
Acme.sh
»
Version:
2.8.5
cpe:2.3:a:acme.sh_project:acme.sh:2.8.5
Acme.sh Project
»
Acme.sh
»
Version:
2.8.6
cpe:2.3:a:acme.sh_project:acme.sh:2.8.6
Acme.sh Project
»
Acme.sh
»
Version:
2.8.7
cpe:2.3:a:acme.sh_project:acme.sh:2.8.7
Acme.sh Project
»
Acme.sh
»
Version:
2.8.8
cpe:2.3:a:acme.sh_project:acme.sh:2.8.8
Acme.sh Project
»
Acme.sh
»
Version:
2.8.9
cpe:2.3:a:acme.sh_project:acme.sh:2.8.9
Acme.sh Project
»
Acme.sh
»
Version:
2.9.0
cpe:2.3:a:acme.sh_project:acme.sh:2.9.0
Acme.sh Project
»
Acme.sh
»
Version:
3.0.1
cpe:2.3:a:acme.sh_project:acme.sh:3.0.1
Acme.sh Project
»
Acme.sh
»
Version:
3.0.2
cpe:2.3:a:acme.sh_project:acme.sh:3.0.2
Acme.sh Project
»
Acme.sh
»
Version:
3.0.3
cpe:2.3:a:acme.sh_project:acme.sh:3.0.3
Acme.sh Project
»
Acme.sh
»
Version:
3.0.4
cpe:2.3:a:acme.sh_project:acme.sh:3.0.4
Acme.sh Project
»
Acme.sh
»
Version:
3.0.5
cpe:2.3:a:acme.sh_project:acme.sh:3.0.5
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved