CVE-2023-25915 CRITICAL

CVE-2023-25915: Authenticated Remote Command Execution in Danfoss AK-SM800A

Vendor Danfoss
Product AK-SM800A
Weakness CWE-20 · Input validation
Published August 21, 2023
Last update January 9, 2025

CVSS base score

9.9/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system.

Key dates

02Disclosure timeline

August 21, 2023 CVE published
January 9, 2025 Record updated