⚠️ CISA Known Exploited Vulnerability
Active ThreatThis vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Active exploitation has been observed in the wild. This poses significant risk to federal enterprises and should be prioritized for immediate patching.
CVE-2023-52163
High CISA KEVVulnerability Description
Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Known Affected Software
2 configuration(s) from 1 vendor(s)
cpe:2.3:o:digiever:ds-2105_pro\+_firmware:3.1.0.71-11:*:*:*:*:*:*:*
cpe:2.3:o:digiever:ds-2105_pro_firmware:3.1.0.71-11:*:*:*:*:*:*:*
References & Resources
-
https://www.akamai.com/blog/security-research/digiever-fix-that-iot-thingcve@mitre.org Exploit Third Party Advisory
-
https://www.txone.com/blog/digiever-fixes-sorely-needed/cve@mitre.org Exploit Third Party Advisory
-
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-52163134c704f-9b21-4f2e-91b3-4a467353bcc0 US Government Resource
-
https://www.fortinet.com/blog/threat-research/shadowv2-casts-a-shadow-over-iot-devices134c704f-9b21-4f2e-91b3-4a467353bcc0 Exploit Third Party Advisory
Severity Details
CISA KEV Status
Listed in CISA's Known Exploited Vulnerabilities catalog
Weakness Type (CWE)
Missing Authorization
- Description
- The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
- Exploit Likelihood
- High
- Typical Severity
- High
- OWASP Top 10
- A01:2021-Broken Access Control
- Abstraction Level
- Class
Key Information
- Published Date
- February 03, 2025
External Resources
Related News Articles
Latest news and updates about CVE-2023-52163
