An improper input validation vulnerability has been found in Lanaccess ONSAFE MonitorHM affecting version 3.7.0. This vulnerability could lead a remote attacker to exploit the checkbox element and perform remote code execution, compromising the entire infrastructure.
Metrics
Affected Vendors & Products
Fixes
Solution
The vulnerability has been fixed in version 4.1.3 (2021 and later). The equipment allows a system administrator user in local mode to configure the system in protected mode, being able to disable access to commands completely.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-17T13:01:40.923Z
Reserved: 2023-11-08T08:46:49.641Z
Link: CVE-2023-6012

Updated: 2024-08-02T08:21:17.001Z

Status : Modified
Published: 2023-11-08T11:15:09.923
Modified: 2024-11-21T08:42:58.650
Link: CVE-2023-6012

No data.

No data.