← All CVEs

CVE-2023-27267

critical · 9

Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system.

9
CVSS
14.2%
EPSS (exploit prob.)
96th
EPSS percentile
2023-04-11
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-306

Affected products

VendorProductAffected versions
sapdiagnostics_agent720

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-27267