← Back

CVE-2023-43743

nvd nist
Published: Dec 8, 2023Modified: May 27, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A SQL injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an authenticated attacker to execute arbitrary SQL queries on the backend database via the filter parameter in requests to the /newapi/ endpoint in the Zultys MX web interface.

Affected (12)

6 products
Mx Se Firmware
Mx Se Ii Firmware
Mx E Firmware
Mx Virtual Firmware
Mx250 Firmware
Mx30 Firmware
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Zultys
Before 16.0.4
From 17.0.6 to 17.0.10
Running on/withPlatform Versions
Zultys
Mx Se
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Zultys
Before 16.0.4
From 17.0.6 to 17.0.10
Running on/withPlatform Versions
Zultys
Mx Se Ii
All versions
Configuration C
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Zultys
Before 16.0.4
From 17.0.6 to 17.0.10
Running on/withPlatform Versions
Zultys
Mx E
All versions
Configuration D
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Zultys
Before 16.0.4
From 17.0.6 to 17.0.10
Running on/withPlatform Versions
Zultys
Mx Virtual
All versions
Configuration E
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Zultys
Before 16.0.4
From 17.0.6 to 17.0.10
Running on/withPlatform Versions
Zultys
Mx250
All versions
Configuration F
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Zultys
Before 16.0.4
From 17.0.6 to 17.0.10
Running on/withPlatform Versions
Zultys
Mx30
All versions

References (4)

Source: cve@mitre.org
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.