An unauthenticated remote attacker is able to perform remote code executiondue to incorrectly sanitized user input in the SetParameter command.
| CVE ID | CVE-2023-49900 |
| Vendor | Unknown Vendor |
| Affected Product | Unknown Product |
| Vulnerability Type | Vulnerability |
| CVSS Score | 9.8 (CRITICAL) |
| EPSS Score | 0.5% probability of exploitation in the next 30 days |
| Actively Exploited | ❌ No known exploitation |
| Patch Status | Pending Vendor Disclosure |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via sentinel_apex) |
An unauthenticated remote attacker is able to perform remote code executiondue to incorrectly sanitized user input in the SetParameter command.
Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.