CVE-2023-22344
CVE-2023-22344
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
05 Mar 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to obtain the password of the debug tool and execute it. As a result of exploiting this vulnerability with CVE-2023-22335 and CVE-2023-22336 vulnerabilities together, it may allow a remote attacker to execute an arbitrary code with SYSTEM privileges by sending a specially crafted script to the affected device.
Affected products
DOS Co., Ltd. · SS1 and Rakuraku PC CloudWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →