« Volver al listado

CVE-2023-46306

Estado: ModificadaMedia (6.6)—

The web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 executes an OS command constructed with unsanitized user input: shell metacharacters in the /admin/gnssAutoAlign.php device_id parameter. This occurs because another thread can be started before the trap that triggers the cleanup function. A successful exploit could allow an authenticated user to execute arbitrary commands with elevated privileges. NOTE: this is different from CVE-2023-0861 and CVE-2023-0862, which were fixed in version 4.6.0.105.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-46306",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-46306",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-12T18:17:05.575956Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@mitre.org",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.4,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.7
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.6,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.7
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:netmodule:netmodule_router_software:4.6.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "netmodule",
          "product": "netmodule_router_software",
          "versions": [
            {
              "status": "affected",
              "version": "4.6.0.0",
              "lessThan": "4.6.0.106",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:netmodule:netmodule_router_software:4.8:*:*:*:*:*:*:*"
          ],
          "vendor": "netmodule",
          "product": "netmodule_router_software",
          "versions": [
            {
              "status": "affected",
              "version": "4.8",
              "lessThan": "4.8.0.101",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2023-10-22T21:15:07.930",
  "references": [
    {
      "url": "https://pentest.blog/advisory-netmodule-router-software-race-condition-leads-to-remote-code-execution/",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://share.netmodule.com/public/system-software/4.6/4.6.0.106/NRSW-RN-4.6.0.106.pdf",
      "tags": [
        "Release Notes"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://share.netmodule.com/public/system-software/4.8/4.8.0.101/NRSW-RN-4.8.0.101.pdf",
      "tags": [
        "Release Notes"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://pentest.blog/advisory-netmodule-router-software-race-condition-leads-to-remote-code-execution/",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://share.netmodule.com/public/system-software/4.6/4.6.0.106/NRSW-RN-4.6.0.106.pdf",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://share.netmodule.com/public/system-software/4.8/4.8.0.101/NRSW-RN-4.8.0.101.pdf",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 executes an OS command constructed with unsanitized user input: shell metacharacters in the /admin/gnssAutoAlign.php device_id parameter. This occurs because another thread can be started before the trap that triggers the cleanup function. A successful exploit could allow an authenticated user to execute arbitrary commands with elevated privileges. NOTE: this is different from CVE-2023-0861 and CVE-2023-0862, which were fixed in version 4.6.0.105."
    },
    {
      "lang": "es",
      "value": "La interfaz de administración web en NetModule Router Software (NRSW) 4.6 anterior a 4.6.0.106 y 4.8 anterior a 4.8.0.101 ejecuta un comando del sistema operativo construido con entrada de usuario no sanitizada: metacaracteres de shell en el parámetro /admin/gnssAutoAlign.php device_id. Esto ocurre porque se puede iniciar otro subproceso antes de la captura que activa la función de limpieza. Un exploit exitoso podría permitir a un usuario autenticado ejecutar comandos arbitrarios con privilegios elevados. NOTA: esto es diferente de CVE-2023-0861 y CVE-2023-0862, que se corrigieron en la versión 4.6.0.105."
    }
  ],
  "lastModified": "2026-06-17T06:30:37.533",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:netmodule:netmodule_router_software:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B651903-7598-4F86-B2C1-53923B573509",
              "versionEndExcluding": "4.6.0.105"
            },
            {
              "criteria": "cpe:2.3:a:netmodule:netmodule_router_software:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B543F356-8395-4F7E-A3C8-1A5DB362533C",
              "versionEndExcluding": "4.7.0.103",
              "versionStartIncluding": "4.7.0.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:netmodule:nb1601:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5C90BC32-C405-4178-B944-9CF39C212C46"
            },
            {
              "criteria": "cpe:2.3:h:netmodule:nb1800:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A80AE348-C415-4B5F-B359-26E2F2A132F7"
            },
            {
              "criteria": "cpe:2.3:h:netmodule:nb1810:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A3CF8E81-2EB5-4CDC-9FC9-CEAF4E1E7514"
            },
            {
              "criteria": "cpe:2.3:h:netmodule:nb2800:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "EFF579A1-A31C-47F3-912A-43F5B4894497"
            },
            {
              "criteria": "cpe:2.3:h:netmodule:nb2810:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "41310FAF-CD23-4126-942D-DA950A96DF3E"
            },
            {
              "criteria": "cpe:2.3:h:netmodule:nb3701:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "962F7AFA-76A3-4F83-AA2C-AB168C644104"
            },
            {
              "criteria": "cpe:2.3:h:netmodule:nb3800:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7120564A-4FE0-403E-A976-9658A665E51A"
            },
            {
              "criteria": "cpe:2.3:h:netmodule:ng800:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0408E588-146F-4AD2-9D58-A12EBA83A697"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}