← Back to browse · API

CVE-2023-27267

Severity
CRITICAL
CVSS
9.0
EPSS
0.14201
Risk score
40.97
CISA KEV
No
PoC
No
Published
2023-04-11
Modified
2025-02-07
First seen
2026-08-07
Aliases
EUVD-2023-31045, GHSA-F5C7-P8W5-6JV3
Products
SAP:Diagnostics Agent (OSCommand Bridge) 720
Sources
euvd EUVD-2023-31045

Description

Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system.

References