CVE-2023-6078

An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution.
References
Link Resource
https://www.3ds.com/vulnerability/advisories Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:3ds:biovia_materials_studio:*:*:*:*:*:*:*:*

History

09 Feb 2024, 20:23

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 9.8
Summary
  • (es) Existe una vulnerabilidad de inyección de comandos del sistema operativo en los productos BIOVIA Materials Studio desde la versión BIOVIA 2021 hasta la versión BIOVIA 2023. La carga de un script perl especialmente manipulado puede provocar la ejecución de comandos arbitrarios.
CPE cpe:2.3:a:3ds:biovia_materials_studio:*:*:*:*:*:*:*:*
References () https://www.3ds.com/vulnerability/advisories - () https://www.3ds.com/vulnerability/advisories - Vendor Advisory
First Time 3ds biovia Materials Studio
3ds

01 Feb 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-01 14:15

Updated : 2024-02-09 20:23


NVD link : CVE-2023-6078

Mitre link : CVE-2023-6078

CVE.ORG link : CVE-2023-6078


JSON object : View

Products Affected

3ds

  • biovia_materials_studio
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')