peter bassill · operator
$ cve CVE-2023-37569 JSON

CVE-2023-37569 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 33.9% (pctl 98)

Patch early

A public exploit exists.

Description

This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. A remote authenticated attacker could exploit this by injecting OS commands on the targeted system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on targeted system.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS33.89% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2023-08-08
Last modified2026-06-17

Affected (1)

VendorProduct
esds.coemagic data center management

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD