CVE-2023-43849

Incorrect access control in firmware upgrade function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to submit a firmware image via HTTP POST requests. This may result in DoS or remote code execution.
References
Link Resource
https://github.com/setersora/pe6208 Exploit Third Party Advisory
https://github.com/setersora/pe6208 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:aten:pe6208_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:aten:pe6208:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-05-28 19:15

Updated : 2026-06-17 06:26


NVD link : CVE-2023-43849

Mitre link : CVE-2023-43849

CVE.ORG link : CVE-2023-43849


JSON object : View

Products Affected

aten

  • pe6208
  • pe6208_firmware
CWE
CWE-284

Improper Access Control