安全研究

安全漏洞
ZPE Systems Nodegrid OS操作系统命令注入漏洞(CVE-2023-43322)

发布日期:2023-10-27
更新日期:2024-01-03

受影响系统:
ZPE Systems ZPE Systems Nodegrid OS >= 5.8.0
ZPE Systems ZPE Systems Nodegrid OS >= 5.6.0
ZPE Systems ZPE Systems Nodegrid OS >= 5.4.0
ZPE Systems ZPE Systems Nodegrid OS >= 5.2.0
ZPE Systems ZPE Systems Nodegrid OS >= 5.10.0
ZPE Systems ZPE Systems Nodegrid OS >= 5.0.0
ZPE Systems ZPE Systems Nodegrid OS < 5.8.11
ZPE Systems ZPE Systems Nodegrid OS < 5.6.14
ZPE Systems ZPE Systems Nodegrid OS < 5.4.17
ZPE Systems ZPE Systems Nodegrid OS < 5.2.20
ZPE Systems ZPE Systems Nodegrid OS < 5.10.4
ZPE Systems ZPE Systems Nodegrid OS < 5.0.18
描述:
CVE(CAN) ID: CVE-2023-43322

ZPE Systems Nodegrid OS是美国ZPE Systems公司的一款操作系统。
ZPE Systems Nodegrid OS多个版本的/v1/system/toolkit/files/端点存在操作系统命令注入漏洞,攻击者可利用该漏洞执行命令。

<*链接:https://psirt.zpesystems.com/portal/en/kb/articles/security-advisory-zpe-ng-2023-001-12-10-2023
*>

建议:
厂商补丁:

ZPE Systems
-----------
ZPE Systems已经为此发布了一个安全公告(ZPE-NG-2023-001)以及相应补丁:
ZPE-NG-2023-001:Security Advisory ZPE-NG-2023-001
链接:https://psirt.zpesystems.com/portal/en/kb/articles/security-advisory-zpe-ng-2023-001-12-10-2023

浏览次数:349
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障