Unknown
CVE-2023-40158
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2023-40158
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
Hidden functionality vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H, NR16H series and DR-16F, DR-8F, DR-4F, DR-16H, DR-8H, DR-4H, DR-4M41 series are no longer supported, therefore updates for those products are not provided.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- dr-16f42a firmware -,
- dr-16f45at firmware -,
- dr-16h firmware -,
- dr-16m52 firmware -,
- dr-16m52-av firmware -,
- dr-4fx1 firmware -,
- dr-4h firmware -,
- dr-4m51-av firmware -,
- dr-8f42a firmware -,
- dr-8f45at firmware -,
- dr-8h firmware -,
- dr-8m52-av firmware -,
- drh8-4m41-a firmware -,
- nr-16f82-16p firmware -,
- nr-16f85-8pra firmware -,
- nr-16m firmware -,
- nr-4f firmware -,
- nr-8f firmware -,
- nr16h firmware -,
- nr4h firmware -,
- nr8-4m71 firmware -,
- nr8-8m72 firmware -,
- nr8h firmware -
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: