CVE-2023-34105 is a critical command injection vulnerability affecting SRS (Simple Realtime Server) versions prior to 5.0.157, 5.0-b1, and 6.0.48. An unauthenticated attacker can achieve Remote Code Execution (RCE) by sending a specially crafted POST request to the /api/v1/snapshots endpoint, injecting arbitrary commands. This vulnerability has a CVSS score of 7.5 (High) due to its network-based attack vector, high impact on confidentiality, integrity, and availability, and relatively low attack complexity, though it requires user interaction. While not currently listed in CISA's KEV catalog, its high EPSS score (0.82764) indicates a significant likelihood of exploitation, and public Nuclei templates exist for detection. There is currently no evidence of active exploitation or widespread community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.137, < 5.0.157CPE matchmatch criteria | cpe:2.3:a:ossrs:simple_realtime_server:*:*:*:*:*:*:*:* | ||
>= 6.0.18, < 6.0.48CPE matchmatch criteria | cpe:2.3:a:ossrs:simple_realtime_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.