OS Command Injection Vulnerability in SolarView Compact by Contec
CVE-2023-27514

8.8HIGH

Key Information:

Vendor
CVE Published:
23 May 2023

What is CVE-2023-27514?

The SolarView Compact SV-CPT-MC310 product line prior to version 8.10 contains a vulnerability that allows remote authenticated attackers to inject OS commands via the download page. This could enable malicious users to execute arbitrary commands on the affected system, potentially compromising its integrity and security. Users of these versions are advised to upgrade to the latest firmware to mitigate this risk. For further details, refer to Contec's security documentation and updates.

Affected Version(s)

SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10, and SV-CPT-MC310F versions prior to Ver.8.10

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.