V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2023-41921Critical

A vulnerability allows attackers to download source code or an executable from a remote location and execute the code without sufficiently …

CVSS
9.8
Critical
EPSS
0.00
p32
Published
2023-01-01
Updated
2023-01-01
Description

A vulnerability allows attackers to download source code or an executable from a remote location and execute the code without sufficiently verifying the origin and integrity of the code. This vulnerability can allow attackers to modify the firmware before uploading it to the system, thus achieving the modification of the target’s integrity to achieve an insecure state.

Tags · CWE
Pre-auth
CWE-494
CAPEC-184
CAPEC-185
CAPEC-186
CAPEC-187
CAPEC-533
CAPEC-538
CAPEC-657
CAPEC-662
CAPEC-691
CAPEC-692
CAPEC-693
CAPEC-695
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.001 · p32
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-187 · CWE-494
└ via CAPEC-662 · CWE-494
└ via CAPEC-186 · CWE-494
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
No vulnerabilities match your filters.