CVE-2023-35189 is a critical remote code execution vulnerability affecting Iagona ScrutisWeb versions 2.1.37 and prior, allowing unauthenticated attackers to upload and execute malicious payloads. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network without user interaction, leading to complete compromise of confidentiality, integrity, and availability. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community attention and media coverage, indicating a high potential for future exploitation. It is not currently listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.1.37CPE matchmatch criteria | cpe:2.3:a:iagona:scrutisweb:*:*:*:*:*:*:*:* | ||
>= 0, <= 2.1.37CPE match | cpe:2.3:a:iagona:scrutisweb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.