Back to Database
Status published
High
CVE-2023-36859
PiiGAB M-Bus Code Injection
Vulnerability Description
PiiGAB M-Bus SoftwarePack 900S does not correctly sanitize user input, which could allow an attacker to inject arbitrary commands.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-36859
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Floris Hendriks and Jeroen Wijenbergh of Radboud University reported these vulnerabilities to CISA.
More from PiiGAB
View All →CVE-2023-35987
PiiGAB M-Bus Use of Hard-coded Credentials
Critical
9.8
CVE-2023-35765
PiiGAB M-Bus Plaintext Storage of a Password
Medium
6.5
CVE-2023-35120
PiiGAB M-Bus Cross-Site Request Forgery
High
8.8
CVE-2023-34995
PiiGAB M-Bus Weak Password Requirements
High
7.5
CVE-2023-34433
PiiGAB M-Bus Use of Password Hash With Insufficient Computational Effort
High
7.5
Affected Vendor
PiiGAB
View all reports →Affected Software
M-Bus SoftwarePack
Vulnerable Versions:
900S
Timeline
Official Publish:
July 6th, 2023
Last Modified:
November 14th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H