CVE-2023-27917

HIGHCVSS 8.8/10EPSS 1.93%

Last modified

CVE-2023-27917 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can access Network Maintenance page to execute arbitrary OS commands with a root privilege. The affected products and versions are as follows: M2M Gateway with the firmware Ver.3.7.10 and earlier (CPS-MG341-ADSC1-111, CPS-MG341-ADSC1-931, CPS-MG341G-ADSC1-111, CPS-MG341G-ADSC1-930, and CPS-MG341G5-ADSC1-931), M2M Controller Integrated Type with firmware Ver.3.7.6 and earlier versions (CPS-MC341-ADSC1-111, CPS-MC341-ADSC1-931, CPS-MC341-ADSC2-111, CPS-MC341G-ADSC1-110, CPS-MC341Q-ADSC1-111, CPS-MC341-DS1-111, CPS-MC341-DS11-111, CPS-MC341-DS2-911, and CPS-MC341-A1-111), and M2M Controller Configurable Type with firmware Ver.3.8.8 and earlier versions (CPS-MCS341-DS1-111, CPS-MCS341-DS1-131, CPS-MCS341G-DS1-130, CPS-MCS341G5-DS1-130, and CPS-MCS341Q-DS1-131).. EPSS estimates a 1.93% chance of exploitation in the next 30 days.

Description

OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can access Network Maintenance page to execute arbitrary OS commands with a root privilege. The affected products and versions are as follows: M2M Gateway with the firmware Ver.3.7.10 and earlier (CPS-MG341-ADSC1-111, CPS-MG341-ADSC1-931, CPS-MG341G-ADSC1-111, CPS-MG341G-ADSC1-930, and CPS-MG341G5-ADSC1-931), M2M Controller Integrated Type with firmware Ver.3.7.6 and earlier versions (CPS-MC341-ADSC1-111, CPS-MC341-ADSC1-931, CPS-MC341-ADSC2-111, CPS-MC341G-ADSC1-110, CPS-MC341Q-ADSC1-111, CPS-MC341-DS1-111, CPS-MC341-DS11-111, CPS-MC341-DS2-911, and CPS-MC341-A1-111), and M2M Controller Configurable Type with firmware Ver.3.8.8 and earlier versions (CPS-MCS341-DS1-111, CPS-MCS341-DS1-131, CPS-MCS341G-DS1-130, CPS-MCS341G5-DS1-130, and CPS-MCS341Q-DS1-131).

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.93%

77.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ContecCps-Mg341-Adsc1-111 Firmware<= 3.7.10
ContecCps-Mg341-Adsc1-931 Firmware<= 3.7.10
ContecCps-Mg341g-Adsc1-111 Firmware<= 3.7.10
ContecCps-Mg341g-Adsc1-930 Firmware<= 3.7.10
ContecCps-Mg341g5-Adsc1-931 Firmware<= 3.7.10
ContecCps-Mc341-Adsc1-111 Firmware<= 3.7.6
ContecCps-Mc341-Adsc1-931 Firmware<= 3.7.6
ContecCps-Mc341-Adsc2-111 Firmware<= 3.7.6
ContecCps-Mc341g-Adsc1-110 Firmware<= 3.7.6
ContecCps-Mc341q-Adsc1-111 Firmware<= 3.7.6
ContecCps-Mc341-Ds1-111 Firmware<= 3.7.6
ContecCps-Mc341-Ds11-111 Firmware<= 3.7.6
ContecCps-Mc341-Ds2-911 Firmware<= 3.7.6
ContecCps-Mc341-A1-111 Firmware<= 3.7.6
ContecCps-Mcs341-Ds1-111 Firmware<= 3.8.8
ContecCps-Mcs341-Ds1-131 Firmware<= 3.8.8
ContecCps-Mcs341g-Ds1-130 Firmware<= 3.8.8
ContecCps-Mcs341g5-Ds1-130 Firmware<= 3.8.8
ContecCps-Mcs341q-Ds1-131 Firmware<= 3.8.8

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-27917?
OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can access Network Maintenance page to execute arbitrary OS commands with a root privilege. The affected products and versions are as follows: M2M Gateway with the firmware Ver.3.7.10 and earlier (CPS-MG341-ADSC1-111, CPS-MG341-ADSC1-931, CPS-MG341G-ADSC1-111, CPS-MG341G-ADSC1-930, and CPS-MG341G5-ADSC1-931), M2M Controller Integrated Type with firmware Ver.3.7.6 and earlier versions (CPS-MC341-ADSC1-111, CPS-MC341-ADSC1-931, CPS-MC341-ADSC2-111, CPS-MC341G-ADSC1-110, CPS-MC341Q-ADSC1-111, CPS-MC341-DS1-111, CPS-MC341-DS11-111, CPS-MC341-DS2-911, and CPS-MC341-A1-111), and M2M Controller Configurable Type with firmware Ver.3.8.8 and earlier versions (CPS-MCS341-DS1-111, CPS-MCS341-DS1-131, CPS-MCS341G-DS1-130, CPS-MCS341G5-DS1-130, and CPS-MCS341Q-DS1-131).
How severe is CVE-2023-27917?
CVE-2023-27917 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 1.93% probability of exploitation in the next 30 days.
How do I fix CVE-2023-27917?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-27917?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST