CVE-2023-1731

In Meinbergs LTOS versions prior to V7.06.013, the configuration file upload function would not correctly validate the input, which would allow an remote authenticated attacker with high privileges to execute arbitrary commands.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:meinbergglobal:lantime_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:meinbergglobal:lantime_m100:-:*:*:*:*:*:*:*
cpe:2.3:h:meinbergglobal:lantime_m200:-:*:*:*:*:*:*:*
cpe:2.3:h:meinbergglobal:lantime_m300:-:*:*:*:*:*:*:*
cpe:2.3:h:meinbergglobal:lantime_m400:-:*:*:*:*:*:*:*
cpe:2.3:h:meinbergglobal:lantime_m600:-:*:*:*:*:*:*:*
cpe:2.3:h:meinbergglobal:lantime_m900:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:39

Type Values Removed Values Added
References () https://www.meinbergglobal.com/english/news/meinberg-security-advisory-mbgsa-2023-02-lantime-firmware-v7-06-013.htm - Vendor Advisory () https://www.meinbergglobal.com/english/news/meinberg-security-advisory-mbgsa-2023-02-lantime-firmware-v7-06-013.htm - Vendor Advisory

Information

Published : 2023-04-24 14:15

Updated : 2024-11-21 07:39


NVD link : CVE-2023-1731

Mitre link : CVE-2023-1731

CVE.ORG link : CVE-2023-1731


JSON object : View

Products Affected

meinbergglobal

  • lantime_m300
  • lantime_m900
  • lantime_m200
  • lantime_m100
  • lantime_m600
  • lantime_firmware
  • lantime_m400
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type