CVE-2023-25911
OS Command Injection in Danfoss AK-EM 100
CVE | CVE-2023-25911 | |||||||||||
Title | OS Command Injection in Danfoss AK-EM 100 | |||||||||||
Credits |
|
|||||||||||
Affected products |
|
|||||||||||
CVSS |
Base score:
9.9
(CRITICAL) |
|||||||||||
References |
|
|||||||||||
Problem type(s) | CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') | |||||||||||
Date published | ||||||||||||
Last modified |
Description
The Danfoss AK-EM 100 web applications allow for OS command injection through the web application parameters.
Workaround(s)
The AK-EM 100 has been declared End of Life (EOL). Danfoss advises phasing out this type of device.
JSON version.