PT-2023-9131 · Synology · Video Station

·

CVE-2023-41288

·

Published

2023-08-28

·

Updated

2024-01-10

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Video Station versions prior to 5.7.2
Description An OS command injection issue has been reported, potentially allowing users to execute commands via a network. The vulnerability is related to the failure to neutralize special elements used in an OS command. If exploited, it could enable a remote attacker to execute arbitrary commands.
Recommendations For versions prior to 5.7.2, update to version 5.7.2 or later to resolve the issue. As a temporary workaround, consider restricting network access to Video Station until the update is applied.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03989
CVE-2023-41288

Affected Products

Video Station