CVE-2023-49565 describes a remote command execution vulnerability in the cbis_manager Podman container, specifically affecting its /api/plugins endpoint. Attackers can exploit this by injecting commands into the X-FILENAME, X-PAGE, and X-FIELD HTTP headers, which are unsafely used in Python's subprocess.Popen function. This allows for arbitrary command execution with root privileges within the container. The vulnerability has a high CVSS score of 8.4, indicating a high impact on confidentiality, integrity, and availability, and can be exploited with low attack complexity over an adjacent network. There is currently no public exploit code (Metasploit, Nuclei, ExploitDB) and no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Nokia | CBIS,NCS | CBIS 22, NCS 22.12, NCS 23.10CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.