Untrusted Data Deserialization Risk in N6854A Geolocation Server by NDS Technologies
CVE-2023-1399
7.8HIGH
What is CVE-2023-1399?
The N6854A Geolocation Server, specifically version 2.4.2, is susceptible to untrusted data deserialization. This vulnerability could enable a malicious actor to exploit the default configuration of the device, potentially leading to privilege escalation and allowing unauthorized remote code execution. Organizations using this server model should assess their exposure and implement the necessary security measures.
Affected Version(s)
N6854A Geolocation Server 0 <= 2.4.2
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
An anonymous individual working with Trend Micro’s Zero Day Initiative reported this vulnerability to CISA.
