Security Advisory

CVE-2023-36622

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-07-05 00:00:00
Last updated 2024-11-21 15:00:56
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated administrators to inject arbitrary OS commands via the timezone parameter.