CVE-2023-31446

In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:cassianetworks:xc1000_firmware:2.1.1.2303082218:*:*:*:*:*:*:*
cpe:2.3:h:cassianetworks:xc1000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:cassianetworks:xc2000_firmware:2.1.1.2303090947:*:*:*:*:*:*:*
cpe:2.3:h:cassianetworks:xc2000:-:*:*:*:*:*:*:*

History

29 Jan 2024, 21:15

Type Values Removed Values Added
References
  • () https://blog.kscsc.online/cves/202331446/md.html -

17 Jan 2024, 01:28

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE NVD-CWE-noinfo
First Time Cassianetworks xc2000
Cassianetworks xc1000 Firmware
Cassianetworks
Cassianetworks xc1000
Cassianetworks xc2000 Firmware
References () https://www.cassianetworks.com - () https://www.cassianetworks.com - Product
References () https://github.com/Dodge-MPTC/CVE-2023-31446-Remote-Code-Execution - () https://github.com/Dodge-MPTC/CVE-2023-31446-Remote-Code-Execution - Exploit, Third Party Advisory
CPE cpe:2.3:h:cassianetworks:xc1000:-:*:*:*:*:*:*:*
cpe:2.3:o:cassianetworks:xc1000_firmware:2.1.1.2303082218:*:*:*:*:*:*:*
cpe:2.3:h:cassianetworks:xc2000:-:*:*:*:*:*:*:*
cpe:2.3:o:cassianetworks:xc2000_firmware:2.1.1.2303090947:*:*:*:*:*:*:*

10 Jan 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-10 03:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-31446

Mitre link : CVE-2023-31446

CVE.ORG link : CVE-2023-31446


JSON object : View

Products Affected

cassianetworks

  • xc1000
  • xc2000
  • xc2000_firmware
  • xc1000_firmware