Vulnerability Details CVE-2023-38323
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 47.3%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-38323
-
cpe:2.3:a:opennds:opennds:10.1.0
-
cpe:2.3:a:opennds:opennds:10.1.1
-
cpe:2.3:a:opennds:opennds:10.1.2
-
cpe:2.3:a:opennds:opennds:5.0.0
-
cpe:2.3:a:opennds:opennds:5.0.1
-
cpe:2.3:a:opennds:opennds:5.1.0
-
cpe:2.3:a:opennds:opennds:5.2.0
-
cpe:2.3:a:opennds:opennds:6.0.0
-
cpe:2.3:a:opennds:opennds:7.0.0
-
cpe:2.3:a:opennds:opennds:7.0.1
-
cpe:2.3:a:opennds:opennds:8.0.0
-
cpe:2.3:a:opennds:opennds:8.1.0
-
cpe:2.3:a:opennds:opennds:8.1.1
-
cpe:2.3:a:opennds:opennds:9.0.0
-
cpe:2.3:a:opennds:opennds:9.1.0
-
cpe:2.3:a:opennds:opennds:9.1.1
-
cpe:2.3:a:opennds:opennds:9.10.0
-
cpe:2.3:a:opennds:opennds:9.2.0
-
cpe:2.3:a:opennds:opennds:9.3.0
-
cpe:2.3:a:opennds:opennds:9.4.0
-
cpe:2.3:a:opennds:opennds:9.5.0
-
cpe:2.3:a:opennds:opennds:9.5.1
-
cpe:2.3:a:opennds:opennds:9.6.0
-
cpe:2.3:a:opennds:opennds:9.7.0
-
cpe:2.3:a:opennds:opennds:9.8.0
-
cpe:2.3:a:opennds:opennds:9.9.0
-
cpe:2.3:a:opennds:opennds:9.9.1