SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-37569

This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component.

HIGH 8.8EPSS 33.9%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 33.9%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. A remote authenticated attacker could exploit this by injecting OS commands on the targeted system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on targeted system.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
33.89% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-78
Affected
esds.co/emagic data center management
Source
vdisclose@cert-in.org.in

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.