CVE-2023-24958
Published May 4, 2023
Last updated 2 years ago
Overview
- Description
- A vulnerability in the IBM TS7700 Management Interface 8.51.2.12, 8.52.200.111, 8.52.102.13, and 8.53.0.63 could allow an authenticated user to submit a specially crafted URL leading to privilege escalation and remote code execution. IBM X-Force ID: 246320.
- Source
- psirt@us.ibm.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
Weaknesses
- nvd@nist.gov
- NVD-CWE-noinfo
- psirt@us.ibm.com
- CWE-78
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:ibm:3957-vec:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "DA5AFD00-4476-4F6D-B94B-CC5DC0AFFA85" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:ibm:3957-vec_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B197CD8D-54E2-484B-8738-76023E622849", "versionEndExcluding": "8.51.2.12", "versionStartIncluding": "8.51.0" }, { "criteria": "cpe:2.3:o:ibm:3957-vec_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E066D44A-254C-411A-B1DD-4A5CDA4158CA", "versionEndExcluding": "8.52.102.13", "versionStartIncluding": "8.52.100.0" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:ibm:3957-ved:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "224332D9-31A8-4EF3-B675-29783295E98F" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:ibm:3957-ved_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "980CFAB9-3673-4204-92C0-ED354DCAE690", "versionEndExcluding": "8.51.2.12", "versionStartIncluding": "8.51.0" }, { "criteria": "cpe:2.3:o:ibm:3957-ved_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C14361A3-98BE-4EC9-8F7C-5B12613AA4B8", "versionEndExcluding": "8.52.102.13", "versionStartIncluding": "8.52.100.0" }, { "criteria": "cpe:2.3:o:ibm:3957-ved_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "25F7347A-BA05-4798-ABBC-8DEA7828DCFD", "versionEndExcluding": "8.52.200.111", "versionStartIncluding": "8.52.200.0" }, { "criteria": "cpe:2.3:o:ibm:3957-ved_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1999ACE8-40C7-4D9E-837A-E53C44F7A6E8", "versionEndExcluding": "8.53.0.63", "versionStartIncluding": "8.53.0" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:ibm:3948-ved:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B531AEEC-2838-4A21-92B4-90BA2D06D1BC" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:ibm:3948-ved_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D76A6F44-751C-49D0-8834-2369F7B7A285", "versionEndIncluding": "8.53.0.63", "versionStartIncluding": "8.53.0" } ], "operator": "OR" } ], "operator": "AND" } ]