Security Advisory

CVE-2023-36622

7.2
HIGH

Vulnerability Description

The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated administrators to inject arbitrary OS commands via the timezone parameter.
Published Date July 5, 2023
Official Source NIST NVD Advisory