Breaking
SecurityDeveloping Story

Critical Remote Code Execution Flaw Discovered in SetParameter Command

A critical vulnerability identified as CVE-2023-49900 allows unauthenticated remote attackers to execute arbitrary code due to improper input sanitization.

··1 month ago·1 min read
teal LED panel
Photo by Adi Goldstein on Unsplash

A security flaw tracked as GHSA-3g8c-pp6x-x9gw, or CVE-2023-49900, has been identified in the SetParameter command. The vulnerability stems from incorrectly sanitized user input, which permits an unauthenticated remote attacker to perform remote code execution.

With a critical CVSS score of 9.8, this vulnerability poses a significant risk to affected systems. The lack of authentication requirements increases the potential impact, as attackers can exploit the flaw remotely without prior access.

Users and administrators are advised to monitor official security updates and apply patches as soon as they are made available to mitigate the risk of unauthorized code execution.

#cve-2023-49900#vulnerability#remote code execution#security advisory

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories