CVE-2023-43743
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
A SQL injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an authenticated attacker to execute arbitrary SQL queries on the backend database via the filter parameter in requests to the /newapi/ endpoint in the Zultys MX web interface.
Affected (12)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 16.0.4 |
| Running on/with | Platform Versions |
|---|---|
Zultys Mx Se | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 16.0.4 |
| Running on/with | Platform Versions |
|---|---|
Zultys Mx Se Ii | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 16.0.4 |
| Running on/with | Platform Versions |
|---|---|
Zultys Mx E | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 16.0.4 |
| Running on/with | Platform Versions |
|---|---|
Zultys Mx Virtual | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 16.0.4 |
| Running on/with | Platform Versions |
|---|---|
Zultys Mx250 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 16.0.4 |
| Running on/with | Platform Versions |
|---|---|
Zultys Mx30 | All versions |
References (4)
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.