9.8
CVSSv3

CVE-2023-45852

Published: 14/10/2023 Updated: 18/10/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated malicious user to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

viessmann vitogate 300 firmware