CVE-2023-49959
26.02.2024, 16:27
In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote attackers to execute arbitrary system commands with root privileges via a crafted filename parameter in POST requests to the /api/updater/ctrl/start_update endpoint.
Vendor | Product | Version |
---|---|---|
indu-sol | profinet-inspektor_nt | 𝑥 < 2.4.1 |
𝑥
= Vulnerable software versions