Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in VR-S1000 firmware Ver. 2.37 and earlier allows an authenticated attacker who can access to the product's command line interface to execute an arbitrary command.
References
Link Resource
https://jvn.jp/en/jp/JVN23771490/ Third Party Advisory
https://www.buffalo.jp/news/detail/20231225-01.html Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: jpcert

Published: 2023-12-26T07:29:17.894Z

Updated: 2023-12-26T07:29:17.894Z

Reserved: 2023-10-25T07:08:55.618Z


Link: CVE-2023-46681

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-26T08:15:10.247

Modified: 2024-01-04T02:47:32.570


Link: CVE-2023-46681

JSON object: View

cve-icon Redhat Information

No data.

CWE