CVE-2023-28725
Last modified
CVE-2023-28725 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in the wild in March 2023. This is fixed in 20221118.48 and 20230120.44.. EPSS estimates a 20.61% chance of exploitation in the next 30 days.
Description
General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in the wild in March 2023. This is fixed in 20221118.48 and 20230120.44.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Generalbytes | Crypto Application Server | 20230120 |
References
- https://www.generalbytes.com/en/support/changelogRelease Notes
- https://www.generalbytes.com/en/support/changelogRelease Notes
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-28725?
How severe is CVE-2023-28725?
How do I fix CVE-2023-28725?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-28718Osprey Pump Controller version 1.01 allows users to perform …8
- CVE-2023-2872A vulnerability classified as problematic has been found in …5.5
- CVE-2023-28720Improper initialization for some Intel(R) PROSet/Wireless an…6.5
- CVE-2023-28722Improper buffer restrictions for some Intel NUC BIOS firmwar…7.8
- CVE-2023-28723Exposure of sensitive information to an unauthorized actor i…5.5
- CVE-2023-28724NGINX Management Suite default file permissions are set such…7.1
- CVE-2023-28726Panasonic AiSEG2 versions 2.80F through 2.93A allows remote …8.8
- CVE-2023-28727Panasonic AiSEG2 versions 2.00J through 2.93A allows adjacen…8.8
- CVE-2023-28728A stack-based buffer overflow in Panasonic Control FPWIN Pro…7.8
- CVE-2023-28729A type confusion vulnerability in Panasonic Control FPWIN Pr…7.8
- CVE-2023-2873A vulnerability classified as critical was found in Twister …7.8
- CVE-2023-28730A memory corruption vulnerability Panasonic Control FPWIN Pr…7.8
Are you affected by CVE-2023-28725?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
