CVE-2023-45599

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/03/2024
Last modified:
03/03/2025

Description

A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web application allows a remote authenticated attacker to upload any arbitrary type of file into the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ailux:imx6:*:*:*:*:*:*:*:* 1.0.7-2 (excluding)