CVE-2023-25911
OS Command Injection in Danfoss AK-EM 100
| CVE | CVE-2023-25911 | |||||||||||
| Title | OS Command Injection in Danfoss AK-EM 100 | |||||||||||
| Credits | 
 | |||||||||||
| Affected products | 
 | |||||||||||
| CVSS | Base score: 
						9.9
						(CRITICAL) | |||||||||||
| References | 
 | |||||||||||
| Problem type(s) | CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') | |||||||||||
| Date published | ||||||||||||
| Last modified | 
Description
			
				The Danfoss AK-EM 100 web applications allow for OS command injection through the web application parameters.
			
		
	
	Workaround(s)
			
				The AK-EM 100 has been declared End of Life (EOL). Danfoss advises phasing out this type of device.
			
			
		
	
	JSON version.