Skip to content
COOEY

EXPOSURES › CVE-2023-49897

CVE-2023-49897

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-12-21 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-49897 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildsupply-chain

FXC AE1021/PE devices allow authenticated attackers to execute OS commands via network, enabling remote code execution.

This OS command injection vulnerability in FXC AE1021 and AE1021PE devices allows authenticated users to execute arbitrary commands over the network, creating a critical RCE risk for DIB organizations relying on these network appliances. Because the vulnerability is actively exploited and linked to ransomware campaigns, vendors must prioritize patching and customers should verify firmware versions immediately to prevent unauthorized access and data exfiltration.

Shame score — Active exploitation of a remote code execution vulnerability in widely deployed network appliances indicates a critical security oversight.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

FXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.