Security Advisory
CVE-2023-27394
9.8
CRITICAL
Vulnerability Description
Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP GET parameter called by DataLogView.php, EventsView.php and AlarmsView.php scripts.
Published Date
March 28, 2023
Official Source
NIST NVD Advisory