Security Advisory

CVE-2023-27394

9.8
CRITICAL

Vulnerability Description

Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP GET parameter called by DataLogView.php, EventsView.php and AlarmsView.php scripts.
Published Date March 28, 2023
Official Source NIST NVD Advisory