An improper input validation vulnerability has been found in Lanaccess ONSAFE MonitorHM affecting version 3.7.0. This vulnerability could lead a remote attacker to exploit the checkbox element and perform remote code execution, compromising the entire infrastructure.
Fixes

Solution

The vulnerability has been fixed in version 4.1.3 (2021 and later). The equipment allows a system administrator user in local mode to configure the system in protected mode, being able to disable access to commands completely.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-09-17T13:01:40.923Z

Reserved: 2023-11-08T08:46:49.641Z

Link: CVE-2023-6012

cve-icon Vulnrichment

Updated: 2024-08-02T08:21:17.001Z

cve-icon NVD

Status : Modified

Published: 2023-11-08T11:15:09.923

Modified: 2024-11-21T08:42:58.650

Link: CVE-2023-6012

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.