In Meinbergs LTOS versions prior to V7.06.013, the configuration file upload function would not correctly validate the input, which would allow an remote authenticated attacker with high privileges to execute arbitrary commands.
References
Link | Resource |
---|---|
https://www.meinbergglobal.com/english/news/meinberg-security-advisory-mbgsa-2023-02-lantime-firmware-v7-06-013.htm | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2023-04-24 14:15
Updated : 2023-05-23 06:15
NVD link : CVE-2023-1731
Mitre link : CVE-2023-1731
CVE.ORG link : CVE-2023-1731
JSON object : View
Products Affected
meinbergglobal
- lantime_firmware
- lantime_m900
- lantime_m100
- lantime_m400
- lantime_m200
- lantime_m300
- lantime_m600
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type