V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2023-30856
CVE
Critical

eDEX-UI is a science fiction terminal emulator. Versions 2.2.8 and prior are vulnerable to cross-site websocket hijacking. When running eDE…

CVSS
10.0
Critical
EPSS
0.00
p26
Published
2023-01-01
Updated
2023-01-01
Description

eDEX-UI is a science fiction terminal emulator. Versions 2.2.8 and prior are vulnerable to cross-site websocket hijacking. When running eDEX-UI and browsing the web, a malicious website can connect to eDEX's internal terminal control websocket, and send arbitrary commands to the shell. The project has been archived since 2021, and as of time of publication there are no plans to patch this issue and release a new version. Some workarounds are available, including shutting down eDEX-UI when browsing the web and ensuring the eDEX terminal runs with lowest possible privileges.

Tags · CWE
Pre-auth
CWE-346
CAPEC-21
CAPEC-59
CAPEC-60
CAPEC-75
CAPEC-76
CAPEC-89
CAPEC-111
CAPEC-141
CAPEC-142
CAPEC-160
CAPEC-384
CAPEC-385
CAPEC-386
CAPEC-387
CAPEC-388
CAPEC-510
Affected products
Edex-ui ≤ 2.2.8
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.003 · p26
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-21 · CWE-346
└ via CAPEC-60 · CWE-346
└ via CAPEC-21 · CWE-346
└ via CAPEC-21 · CWE-346
└ via CAPEC-60 · CWE-346
└ via CAPEC-141 · CWE-346
└ via CAPEC-142 · CWE-346
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
edex-ui*Tracked
Source databases
CVE