vendor:
Vitogate 300
by:
ByteHunter
6.1
CVSS
HIGH
Remote Code Execution (RCE)
78
CWE
Product Name: Vitogate 300
Affected Version From: Up to 2.1.3.0
Affected Version To: 2.1.3.0
Patch Exists: NO
Related CWE: CVE-2023-5702 & CVE-2023-5222
CPE: a:viessmann:vitogate:2.1.3.0
Platforms Tested:
2023
Viessmann Vitogate 300 <= 2.1.3.0 - Remote Code Execution (RCE)
The Viessmann Vitogate 300 with versions up to 2.1.3.0 is vulnerable to remote code execution. By sending a crafted request to the target device, an attacker can execute arbitrary commands on the system. This vulnerability has been assigned CVE-2023-5702 & CVE-2023-5222.
Mitigation:
Update to version 2.1.4.0 or later to mitigate this vulnerability. Additionally, restrict network access to the device to trusted sources only.