CVE-2023-41109 is a critical unauthenticated OS Command Injection vulnerability affecting Patton SmartNode SN200 devices running firmware version 3.21.2-23021. With a CVSS score of 9.8, this flaw allows remote attackers to execute arbitrary commands with high impact on confidentiality, integrity, and availability, requiring no user interaction or authentication. While not currently listed on the KEV catalog, a Nuclei template exists for detection, indicating potential for exploitation. Despite its high EPSS and FAUCET Risk Score, there is currently no public exploit code on Metasploit or ExploitDB, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.21.2-23021CPE matchmatch criteria | cpe:2.3:o:patton:smartnode_sn200_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.