Description
A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web application allows a remote authenticated attacker to upload any arbitrary type of file into the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-49891 | A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web application allows a remote authenticated attacker to upload any arbitrary type of file into the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2. |
References
History
No history.
Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2024-08-02T20:21:16.689Z
Reserved: 2023-10-09T08:26:54.317Z
Link: CVE-2023-45599
Updated: 2024-08-02T20:21:16.689Z
Status : Awaiting Analysis
Published: 2024-03-05T12:15:47.433
Modified: 2024-11-21T08:27:02.223
Link: CVE-2023-45599
No data.
OpenCVE Enrichment
Updated: 2025-07-12T23:05:52Z
Weaknesses
EUVD