CVE-2023-38585
CVE-2023-38585
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.8%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
23 Aug 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H, NR16H series and DR-16F, DR-8F, DR-4F, DR-16H, DR-8H, DR-4H, DR-4M41 series are no longer supported, therefore updates for those products are not provided.
Affected products
CBC Co.,Ltd. · DR-16F, DR-8F, DR-4F, DR-16H, DR-8H, DR-4H, DR-4M41 seriesCBC Co.,Ltd. · DR-16M, DR-8M, DR-4M51 seriesCBC Co.,Ltd. · NR-4F, NR-8F, NR-16F seriesCBC Co.,Ltd. · NR4H, NR8H, NR16H seriesCBC Co.,Ltd. · NR-4M, NR-8M, NR-16M seriesWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →