CVE-2023-23912
09.02.2023, 20:15
A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with their DHCPv6 prefix delegation set to dhcpv6-stateless or dhcpv6-stateful, allows a malicious actor directly connected to the WAN interface of an affected device to create a remote code execution vulnerability.
Vendor | Product | Version |
---|---|---|
ui | usg_firmware | 𝑥 < 4.4.57 |
ui | usg-pro-4_firmware | 𝑥 < 4.4.57 |
ui | er-10x_firmware | 𝑥 < 2.0.9 |
ui | er-10x_firmware | 2.0.9 |
ui | er-10x_firmware | 2.0.9:hotfix2 |
ui | er-10x_firmware | 2.0.9:hotfix4 |
ui | er-10x_firmware | 2.0.9:hotfix5 |
ui | er-12_firmware | 𝑥 < 2.0.9 |
ui | er-12_firmware | 2.0.9 |
ui | er-12_firmware | 2.0.9:hotfix2 |
ui | er-12_firmware | 2.0.9:hotfix4 |
ui | er-12_firmware | 2.0.9:hotfix5 |
ui | er-12p_firmware | 𝑥 < 2.0.9 |
ui | er-12p_firmware | 2.0.9 |
ui | er-12p_firmware | 2.0.9:hotfix2 |
ui | er-12p_firmware | 2.0.9:hotfix4 |
ui | er-12p_firmware | 2.0.9:hotfix5 |
ui | er-4_firmware | 𝑥 < 2.0.9 |
ui | er-4_firmware | 2.0.9 |
ui | er-4_firmware | 2.0.9:hotfix2 |
ui | er-4_firmware | 2.0.9:hotfix4 |
ui | er-4_firmware | 2.0.9:hotfix5 |
ui | er-6p_firmware | 𝑥 < 2.0.9 |
ui | er-6p_firmware | 2.0.9 |
ui | er-6p_firmware | 2.0.9:hotfix2 |
ui | er-6p_firmware | 2.0.9:hotfix4 |
ui | er-6p_firmware | 2.0.9:hotfix5 |
ui | er-8-xg_firmware | 𝑥 < 2.0.9 |
ui | er-8-xg_firmware | 2.0.9 |
ui | er-8-xg_firmware | 2.0.9:hotfix2 |
ui | er-8-xg_firmware | 2.0.9:hotfix4 |
ui | er-8-xg_firmware | 2.0.9:hotfix5 |
ui | er-x_firmware | 𝑥 < 2.0.9 |
ui | er-x_firmware | 2.0.9 |
ui | er-x_firmware | 2.0.9:hotfix2 |
ui | er-x_firmware | 2.0.9:hotfix4 |
ui | er-x_firmware | 2.0.9:hotfix5 |
ui | er-x-sfp_firmware | 𝑥 < 2.0.9 |
ui | er-x-sfp_firmware | 2.0.9 |
ui | er-x-sfp_firmware | 2.0.9:hotfix2 |
ui | er-x-sfp_firmware | 2.0.9:hotfix4 |
ui | er-x-sfp_firmware | 2.0.9:hotfix5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-75 - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)The software does not adequately filter user-controlled input for special elements with control implications.
- CWE-94 - Improper Control of Generation of Code ('Code Injection')The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.