CVE-2023-28390

medium

Description

Privilege escalation vulnerability in SR-7100VN firmware Ver.1.38(N) and earlier and SR-7100VN #31 firmware Ver.1.21 and earlier allows a network-adjacent attacker with administrative privilege of the affected product to obtain an administrative privilege of the OS (Operating System). As a result, an arbitrary OS command may be executed.

References

https://www.icom.co.jp/news/7239/

https://jvn.jp/en/jp/JVN80476232/

Details

Source: Mitre, NVD

Published: 2023-05-23

Updated: 2023-05-30

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:A/AC:L/Au:M/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 6.8

Vector: CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Severity: Medium