CVE-2023-37569

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
08/08/2023
Last modified:
13/02/2025

Description

This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. A remote authenticated attacker could exploit this by injecting OS commands on the targeted system.<br /> <br /> Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on targeted system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:esds.co:emagic_data_center_management:*:*:*:*:*:*:*:* 6.0 (including)