Untrusted Data Deserialization Risk in N6854A Geolocation Server by NDS Technologies
CVE-2023-1399

7.8HIGH

Key Information:

Vendor
CVE Published:
27 March 2023

What is CVE-2023-1399?

The N6854A Geolocation Server, specifically version 2.4.2, is susceptible to untrusted data deserialization. This vulnerability could enable a malicious actor to exploit the default configuration of the device, potentially leading to privilege escalation and allowing unauthorized remote code execution. Organizations using this server model should assess their exposure and implement the necessary security measures.

Affected Version(s)

N6854A Geolocation Server 0 <= 2.4.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

An anonymous individual working with Trend Micro’s Zero Day Initiative reported this vulnerability to CISA.
.