CVE-2023-40158
high-risk
Published 2023-08-23
Hidden functionality vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H, NR16H series and DR-16F, DR-8F, DR-4F, DR-16H, DR-8H, DR-4H, DR-4M41 series are no longer supported, therefore updates for those products are not provided.
Do I need to act?
~
5.0% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.8/10
High
NETWORK
/ LOW complexity
Affected Products (20)
Nr4H Firmware
Nr8H Firmware
Nr16H Firmware
Dr-16F42A Firmware
Dr-16F45At Firmware
Dr-8F42A Firmware
Dr-8F45At Firmware
Dr-4Fx1 Firmware
Dr-16H Firmware
Dr-8H Firmware
Dr-4H Firmware
Drh8-4M41-A Firmware
Nr8-4M71 Firmware
Nr8-8M72 Firmware
Nr-16M Firmware
Nr-16F85-8Pra Firmware
Nr-16F82-16P Firmware
Nr-4F Firmware
Nr-8F Firmware
Dr-16M52 Firmware
Affected Vendors
References (6)
Third Party Advisory
https://jvn.jp/en/vu/JVNVU92545432/
Third Party Advisory
https://jvn.jp/en/vu/JVNVU92545432/
59
/ 100
high-risk
Severity
30/34 · Critical
Exploitability
8/34 · Low
Exposure
21/34 · High