OS Command Injection Vulnerability in NEC Platforms DT900 and DT900S Series
CVE-2023-3741

9.8CRITICAL

What is CVE-2023-3741?

An OS command injection vulnerability exists in the NEC Platforms DT900 and DT900S Series devices, potentially allowing an attacker to execute arbitrary commands on the affected devices. This security gap can lead to unauthorized access and manipulation of the device's operating system, significantly compromising the integrity and confidentiality of the system. Ensuring timely patching and security measures is essential for all users of these series.

Affected Version(s)

ITK-12D-1(BK)TEL all versions

ITK-12D-1P(BK)TEL all versions

ITK-12DG-1P(BK)TEL all versions

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mr. Gianluca Altomani.
.