CVE Vulnerabilities

CVE-2023-44317

Acceptance of Extraneous Untrusted Data With Trusted Data

Published: Nov 14, 2023 | Modified: Feb 13, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Affected products do not properly validate the content of uploaded X509 certificates which could allow an attacker with administrative privileges to execute arbitrary code on the device.

Weakness

The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.

Affected Software

Name Vendor Start Version End Version
Scalance_xb208_(e/ip)_firmware Siemens - (including) - (including)

References