CVE Feed

    Dashboard / CVE / CVE-2023-22855

    CVE-2023-22855

    Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 8088. A user-controllable path is handed to a path-concatenation method (Path.Combine from .NET) without proper sanitisation. This yields the possibility of including local files, as well as remote files on SMB shares. If one provides a file with the extension .t4, it is rendered with the .NET templating engine mono/t4, which can execute code.

    Published:Feb 15, 2023
    Last Modified:Mar 19, 2025
    EPS:Feb 15, 2023
    EPSS Score:0.63397
    CVSS Score:9.8

    Affected Products

    Vendor
    Kardex
    Product
    Kardex Control Center

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High