Control By Web X-600M devices run Lua scripts and are vulnerable to code injection, which could allow an attacker to remotely execute arbitrary code.
No analysis available yet.
Vendor Solution
Control By Web has provided a fix and recommends applying the updates for the following products: * * X-600M: Update firmware to v1.16.00 https://www.controlbyweb.com/firmware/X600M_FieldUpdate_V1.16.00.zip or later
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-27651 | Control By Web X-600M devices run Lua scripts and are vulnerable to code injection, which could allow an attacker to remotely execute arbitrary code. |
| Link | Providers |
|---|---|
| https://www.cisa.gov/uscert/ics/advisories/icsa-23-040-01 |
|
Thu, 16 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T21:57:22.829Z
Reserved: 2023-01-12T22:40:50.503Z
Link: CVE-2023-23551
Updated: 2024-08-02T10:35:33.268Z
Status : Modified
Published: 2023-02-13T18:15:11.400
Modified: 2024-11-21T07:46:24.247
Link: CVE-2023-23551
No data.
OpenCVE Enrichment
No data.
EUVD