CVE-2023-2625

Published Jun 28, 2023

Last updated 5 months ago

Overview

Description
A vulnerability exists that can be exploited by an authenticated client that is connected to the same network segment as the CoreTec 4, having any level of access VIEWER to ADMIN. To exploit the vulnerability the attacker can inject shell commands through a particular field of the web user interface that will be executed by the system.
Source
cybersecurity@hitachienergy.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
8
Impact score
5.9
Exploitability score
2.1
Vector string
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

cybersecurity@hitachienergy.com
CWE-78
nvd@nist.gov
CWE-78

Social media

Hype score
Not currently trending

Configurations