HIGH🇵🇱 Wersja polska

CVE-2023-36859

CVSS 8.8v3.1pub. 2023-07-06upd. 2024-11-21

PiiGAB M-Bus SoftwarePack 900S does not correctly sanitize user input, which could allow an attacker to inject arbitrary commands.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Piigab M Bus 900s

    HW
    Piigab
    all versions
  • Piigab M Bus 900s Firmware

    OS
    Piigab
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-35987CRITICAL9.8PL ✓same product

Zakodowane na stałe dane uwierzytelniające w Piigab M-Bus 900S

CVE-2023-32652HIGH8.0same product

PiiGAB M-Bus does not validate identification strings before processing, which could make it vulnerab...

CVE-2023-34433HIGH7.5same product

PiiGAB M-Bus stores passwords using a weak hash algorithm.

CVE-2023-34995HIGH7.5same product

There are no requirements for setting a complex password for PiiGAB M-Bus, which could contribu...

CVE-2023-35120HIGH8.8same product

PiiGAB M-Bus is vulnerable to cross-site request forgery. An attacker who wants to execute a certain command ...