CVE-2023-38318

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
26/01/2024
Last modified:
20/06/2025

Description

An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opennds:opennds:*:*:*:*:*:*:*:* 10.1.3 (excluding)