Incorrect Access Control in Firmware Upgrade Function Leads to DoS and Remote Code Execution
CVE-2023-43849

6.5MEDIUM

Key Information:

Vendor

Aten

Vendor
CVE Published:
28 May 2024

What is CVE-2023-43849?

The Aten PE6208 series is affected by a vulnerability that arises from improper access control in the firmware upgrade function of its web interface. This weakness allows remote authenticated users to exploit the system by submitting unauthorized firmware images through HTTP POST requests. The consequences of this vulnerability include the potential for denial of service (DoS) or remote code execution, making it critical for users to verify their firmware integrity and apply necessary security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.