TROYANOSYVIRUS
Back to CVEs

CVE-2023-29412

CRITICAL
9.8

Description

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published4/18/2023
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

microsoft:windows_10microsoft:windows_11microsoft:windows_server_2016microsoft:windows_server_2019microsoft:windows_server_2022schneider-electric:apc_easy_ups_online_monitoring_softwareschneider-electric:easy_ups_online_monitoring_software

Weaknesses (CWE)

CWE-78

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.