Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-35812

CVSS 5.3 · Medium EPSS 0.14% · P33
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-35812

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
An issue was discovered in the Amazon Linux packages of OpenSSH 7.4 for Amazon Linux 1 and 2, because of an incomplete fix for CVE-2019-6111 within these specific packages. The fix had only covered cases where an absolute path is passed to scp. When a relative path is used, there is no verification that the name of a file received by the client matches the file requested. Fixed packages are available with numbers 7.4p1-22.78.amzn1 and 7.4p1-22.amzn2.0.2.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
OpenSSH 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OpenSSH(OpenBSD Secure Shell)是加拿大OpenBSD计划组的一套用于安全访问远程计算机的连接工具。该工具是SSH协议的开源实现,支持对所有的传输进行加密,可有效阻止窃听、连接劫持以及其他网络级的攻击。 Amazon Linux 1和2 的 OpenSSH 7.4版本存在安全漏洞,该漏洞源于在使用相对路径时,不会验证客户端接收到的文件名是否与请求的文件匹配。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2023-35812

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-35812

登录查看更多情报信息。

Same Patch Batch · n/a · 2024-04-03 · 36 CVEs total

CVE-2024-282196.7 MEDIUMPillow 安全漏洞
CVE-2024-32703.8 LOWThingsBoard AdvancedFeature access control
CVE-2024-29413Webasyst 跨站脚本漏洞
CVE-2024-27706Huly Platform 跨站脚本漏洞
CVE-2024-27705Leantime Systems Leantime 跨站脚本漏洞
CVE-2023-52043D-Link COVR 多款产品安全漏洞
CVE-2024-27674Macro Expert 安全漏洞
CVE-2023-45552VeridiumID 安全漏洞
CVE-2023-44040VeridiumID 安全漏洞
CVE-2023-44039VeridiumID 安全漏洞
CVE-2023-44038VeridiumID 安全漏洞
CVE-2024-28275Puwell Cloud Tech 360Eyes Pro 安全漏洞
CVE-2024-30572Netgear R6850 安全漏洞
CVE-2024-30571Netgear R6850 安全漏洞
CVE-2024-30570Netgear R6850 安全漏洞
CVE-2024-30569Netgear R6850 安全漏洞
CVE-2024-30568NETGEAR R6850 安全漏洞
CVE-2024-28589Axigen 安全漏洞
CVE-2024-31013emlog 安全漏洞
CVE-2024-28755Mbed TLS 安全漏洞

Showing top 20 of 36 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2023-35812

No comments yet


Leave a comment