CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.2. It may be remotely exploitable.
CVE
CVE-2023-36622
Severity
HIGH
CVSS
7.2
EPSS
1.37%
Original NVD Description
The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated administrators to inject arbitrary OS commands via the timezone parameter.
Related CVEs
Other vulnerabilities affecting the same vendor(s)