CVE-2023-0978

A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI command. The vulnerability allows the attack
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mcafee:advanced_threat_defense:*:*:*:*:*:*:*:*
cpe:2.3:a:trellix:intelligent_sandbox:5.0:*:*:*:*:*:*:*
cpe:2.3:a:trellix:intelligent_sandbox:5.2:*:*:*:*:*:*:*

History

07 Nov 2023, 04:02

Type Values Removed Values Added
Summary A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI command. The vulnerability allows the attack A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI command. The vulnerability allows the attack

17 Mar 2023, 04:03

Type Values Removed Values Added
CWE CWE-77
References (MISC) https://kcm.trellix.com/corporate/index?page=content&id=SB10397 - (MISC) https://kcm.trellix.com/corporate/index?page=content&id=SB10397 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.7
CPE cpe:2.3:a:mcafee:advanced_threat_defense:*:*:*:*:*:*:*:*
cpe:2.3:a:trellix:intelligent_sandbox:5.0:*:*:*:*:*:*:*
cpe:2.3:a:trellix:intelligent_sandbox:5.2:*:*:*:*:*:*:*
First Time Mcafee
Trellix
Mcafee advanced Threat Defense
Trellix intelligent Sandbox

13 Mar 2023, 14:48

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-13 14:15

Updated : 2023-12-10 14:48


NVD link : CVE-2023-0978

Mitre link : CVE-2023-0978

CVE.ORG link : CVE-2023-0978


JSON object : View

Products Affected

mcafee

  • advanced_threat_defense

trellix

  • intelligent_sandbox
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')