// For flags

CVE-2023-24958

IBM TS7700 Management Interface command injection

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in the IBM TS7700 Management Interface 8.51.2.12, 8.52.200.111, 8.52.102.13, and 8.53.0.63 could allow an authenticated user to submit a specially crafted URL leading to privilege escalation and remote code execution. IBM X-Force ID: 246320.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-02-01 CVE Reserved
  • 2023-05-04 CVE Published
  • 2024-08-02 CVE Updated
  • 2024-10-27 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ibm
Search vendor "Ibm"
3957-vec Firmware
Search vendor "Ibm" for product "3957-vec Firmware"
>= 8.51.0 < 8.51.2.12
Search vendor "Ibm" for product "3957-vec Firmware" and version " >= 8.51.0 < 8.51.2.12"
-
Affected
in Ibm
Search vendor "Ibm"
3957-vec
Search vendor "Ibm" for product "3957-vec"
--
Safe
Ibm
Search vendor "Ibm"
3957-vec Firmware
Search vendor "Ibm" for product "3957-vec Firmware"
>= 8.52.100.0 < 8.52.102.13
Search vendor "Ibm" for product "3957-vec Firmware" and version " >= 8.52.100.0 < 8.52.102.13"
-
Affected
in Ibm
Search vendor "Ibm"
3957-vec
Search vendor "Ibm" for product "3957-vec"
--
Safe
Ibm
Search vendor "Ibm"
3957-ved Firmware
Search vendor "Ibm" for product "3957-ved Firmware"
>= 8.51.0 < 8.51.2.12
Search vendor "Ibm" for product "3957-ved Firmware" and version " >= 8.51.0 < 8.51.2.12"
-
Affected
in Ibm
Search vendor "Ibm"
3957-ved
Search vendor "Ibm" for product "3957-ved"
--
Safe
Ibm
Search vendor "Ibm"
3957-ved Firmware
Search vendor "Ibm" for product "3957-ved Firmware"
>= 8.52.100.0 < 8.52.102.13
Search vendor "Ibm" for product "3957-ved Firmware" and version " >= 8.52.100.0 < 8.52.102.13"
-
Affected
in Ibm
Search vendor "Ibm"
3957-ved
Search vendor "Ibm" for product "3957-ved"
--
Safe
Ibm
Search vendor "Ibm"
3957-ved Firmware
Search vendor "Ibm" for product "3957-ved Firmware"
>= 8.52.200.0 < 8.52.200.111
Search vendor "Ibm" for product "3957-ved Firmware" and version " >= 8.52.200.0 < 8.52.200.111"
-
Affected
in Ibm
Search vendor "Ibm"
3957-ved
Search vendor "Ibm" for product "3957-ved"
--
Safe
Ibm
Search vendor "Ibm"
3957-ved Firmware
Search vendor "Ibm" for product "3957-ved Firmware"
>= 8.53.0 < 8.53.0.63
Search vendor "Ibm" for product "3957-ved Firmware" and version " >= 8.53.0 < 8.53.0.63"
-
Affected
in Ibm
Search vendor "Ibm"
3957-ved
Search vendor "Ibm" for product "3957-ved"
--
Safe
Ibm
Search vendor "Ibm"
3948-ved Firmware
Search vendor "Ibm" for product "3948-ved Firmware"
>= 8.53.0 <= 8.53.0.63
Search vendor "Ibm" for product "3948-ved Firmware" and version " >= 8.53.0 <= 8.53.0.63"
-
Affected
in Ibm
Search vendor "Ibm"
3948-ved
Search vendor "Ibm" for product "3948-ved"
--
Safe