CVE-2023-45599
MEDIUMDescription
A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web application allows a remote authenticated attacker to upload any arbitrary type of file into the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ailux | imx6 |
References
Frequently Asked Questions
What is CVE-2023-45599? +
How severe is CVE-2023-45599? +
What products are affected by CVE-2023-45599? +
How do I check if I'm vulnerable to CVE-2023-45599? +
Related Vulnerabilities
Maho is a free and open source ecommerce platform. In Maho prior to 25.9.0, an authenticated staff user with access …
picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft …
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the audio transcription upload …
Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison …
Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 …
Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File