Description
Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all versions allows a attacker to execute an arbitrary OS command with the root privilege, after obtaining a high privilege exploiting CVE-2023-3330 and CVE-2023-3331 vulnerabilities.
Published: 2023-06-28
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

Stop using the products or remove the USB storage.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-44001 Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all versions allows a attacker to execute an arbitrary OS command with the root privilege, after obtaining a high privilege exploiting CVE-2023-3330 and CVE-2023-3331 vulnerabilities.
History

Wed, 04 Dec 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Nec Aterm Wf300hp Aterm Wf300hp Firmware Aterm Wg1400hp Aterm Wg1400hp Firmware Aterm Wg1800hp Aterm Wg1800hp2 Aterm Wg1800hp2 Firmware Aterm Wg1800hp Firmware Aterm Wg2200hp Aterm Wg2200hp Firmware Aterm Wg2600hp Aterm Wg2600hp2 Aterm Wg2600hp2 Firmware Aterm Wg2600hp Firmware Aterm Wg300hp Aterm Wg300hp Firmware Aterm Wg600hp Aterm Wg600hp Firmware Aterm Wr8170n Aterm Wr8170n Firmware Aterm Wr8175n Aterm Wr8175n Firmware Aterm Wr8370n Aterm Wr8370n Firmware Aterm Wr8600n Aterm Wr8600n Firmware Aterm Wr8700n Aterm Wr8700n Firmware Aterm Wr8750n Aterm Wr8750n Firmware Aterm Wr9300n Aterm Wr9300n Firmware Aterm Wr9500n Aterm Wr9500n Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: NEC

Published:

Updated: 2024-12-04T20:54:19.552Z

Reserved: 2023-06-20T01:14:11.982Z

Link: CVE-2023-3333

cve-icon Vulnrichment

Updated: 2024-08-02T06:55:00.761Z

cve-icon NVD

Status : Modified

Published: 2023-06-28T02:15:49.713

Modified: 2024-11-21T08:17:02.283

Link: CVE-2023-3333

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses