Security Advisory

CVE-2023-28725

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-03-21 00:00:00
Last updated 2025-02-26 16:57:15
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in the wild in March 2023. This is fixed in 20221118.48 and 20230120.44.