CVE-2023-49897
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- FXC AE1021, AE1021PE OS Command Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 51% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-78
מוצרים מושפעים
fxc: ae1021 firmware; fxc: ae1021; fxc: ae1021pe firmware; fxc: ae1021pe
קישורים
- https://www.fxc.jp/news/20231206 Release NotesVendor Advisory
- https://www.fxc.jp/news/20231206 Release NotesVendor Advisory
- https://www.akamai.com/blog/security-research/zero-day-vulnerability-spreading… ExploitThird Party Advisory
- https://www.akamai.com/blog/security-research/zero-day-vulnerability-spreading… ExploitThird Party Advisory
- https://jvn.jp/en/vu/JVNVU92152057/ Third Party Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-355-01 Third Party AdvisoryUS Government Resource
- https://jvn.jp/en/vu/JVNVU92152057/ Third Party Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-355-01 Third Party AdvisoryUS Government Resource
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource