Command Injection Vulnerability of ZTE's ZXCLOUD iRAI
CVE-2023-41783

4.3MEDIUM

Key Information:

Vendor

Zte

Vendor
CVE Published:
3 January 2024

What is CVE-2023-41783?

A command injection vulnerability exists in ZTE's ZXCLOUD iRAI due to insufficient validation of user inputs. This flaw allows attackers to execute arbitrary commands, potentially leading to the escalation of local privileges. Such vulnerabilities can be leveraged by malicious entities to gain unauthorized access and control over affected systems, posing significant risks to data integrity and confidentiality. Organizations utilizing ZXCLOUD iRAI should prioritize applying recommended mitigations and patches as soon as possible to safeguard against exploitation.

Affected Version(s)

ZXCLOUD iRAI Windows All versions up to 7.22.11P2 <= 7.22.11P2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.