CVE-2023-28343

CVSS V2 None CVSS V3 None
Description
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.
Overview
  • CVE ID
  • CVE-2023-28343
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Modified
  • Published Version
  • 2023-03-14T20:15:10
  • Last Modified Date
  • 2023-04-10T20:15:11
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:o:apsystems:energy_communication_unit_firmware:c1.2.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:apsystems:energy_communication_unit:-:*:*:*:*:*:*:* 0 OR
History
Created Old Value New Value Data Type Notes
2023-04-17 06:29:07 Added to TrackCVE
2023-04-17 06:29:09 Weakness Enumeration new