CVE-2023-27267 is a critical vulnerability in SAP Diagnostics Agent version 720, stemming from missing authentication and insufficient input validation in its OSCommand Bridge. An attacker with deep system knowledge can exploit this to execute arbitrary scripts on connected agents, leading to a complete compromise of confidentiality, integrity, and availability. Rated 8.1 HIGH on CVSS, this vulnerability has a network attack vector and high impact, but requires high attack complexity. While not currently listed in CISA's KEV catalog and lacking public exploit code, it has garnered significant community discussion and media coverage, indicating awareness of its potential severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
720CPE matchmatch criteria | cpe:2.3:a:sap:diagnostics_agent:720:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.