CVE-2023-6260

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Brivo ACS100, ACS300 allows OS Command Injection, Bypassing Physical Security.This issue affects ACS100 (Network Adjacent Access), ACS300 (Physical Access): from 5.2.4 before 6.2.4.3.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:brivo:acs100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:brivo:acs100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:brivo:acs300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:brivo:acs300:-:*:*:*:*:*:*:*

History

05 Feb 2025, 22:35

Type Values Removed Values Added
References () https://support.brivo.com/l/en/article/g82txdwepa-brivo-firmware-release-notes#brivo_firmware_release_6_2_4_3 - () https://support.brivo.com/l/en/article/g82txdwepa-brivo-firmware-release-notes#brivo_firmware_release_6_2_4_3 - Release Notes
References () https://sra.io/advisories/ - () https://sra.io/advisories/ - Third Party Advisory
CWE CWE-78
First Time Brivo acs100
Brivo acs300 Firmware
Brivo acs100 Firmware
Brivo
Brivo acs300
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:o:brivo:acs100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:brivo:acs300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:brivo:acs100:-:*:*:*:*:*:*:*
cpe:2.3:h:brivo:acs300:-:*:*:*:*:*:*:*

21 Feb 2024, 15:15

Type Values Removed Values Added
References
  • () https://support.brivo.com/l/en/article/g82txdwepa-brivo-firmware-release-notes#brivo_firmware_release_6_2_4_3 -

19 Feb 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-19 22:15

Updated : 2025-02-05 22:35


NVD link : CVE-2023-6260

Mitre link : CVE-2023-6260


JSON object : View

Products Affected

brivo

  • acs300_firmware
  • acs300
  • acs100_firmware
  • acs100
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')