CVE-2023-0830 EXPLOIT
6.3
MEDIUM · CVSS 3.1 · EPSS 20.9% (pctl 97)
Patch early
A public exploit exists.
Description
A vulnerability classified as critical has been found in EasyNAS 1.1.0. Affected is the function system of the file /backup.pl. The manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.
Scoring
| CVSS | 6.3 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| EPSS | 20.86% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2023-02-14 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| easynas | easynas |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | EasyNas 1.1.0 - OS Command Injection | 2023-04-06 |
References
→ the Explorer · watch your stack · NVD