peter bassill · operator
$ cve CVE-2023-0830 JSON

CVE-2023-0830 EXPLOIT

6.3
MEDIUM · CVSS 3.1 · EPSS 20.9% (pctl 97)

Patch early

A public exploit exists.

Description

A vulnerability classified as critical has been found in EasyNAS 1.1.0. Affected is the function system of the file /backup.pl. The manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

Scoring

CVSS6.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS20.86% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploityes
Published2023-02-14
Last modified2026-06-17

Affected (1)

VendorProduct
easynaseasynas

Public exploits

SourceTitleDate
exploit-dbEasyNas 1.1.0 - OS Command Injection2023-04-06

References

→ the Explorer  ·  watch your stack  ·  NVD