CVE-2023-38317
Description
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
OpenNDS before 10.1.3 fails to sanitize network interface name in configuration, allowing attackers with file access to execute arbitrary OS commands.
Vulnerability
The vulnerability resides in OpenNDS versions before 10.1.3. The software does not properly sanitize the network interface name entry in its configuration file. This allows an attacker who has direct or indirect access to the configuration file to inject arbitrary commands. The affected versions are all prior to 10.1.3 [1][2].
Exploitation
To exploit, an attacker must have the ability to modify the configuration file, either through direct file system access or via any mechanism that allows writing to the configuration (e.g., a compromised web interface). The attacker can insert a malicious value for the network interface name containing command injection payloads. When OpenNDS processes the configuration, the injected commands are executed.
Impact
Successful exploitation leads to arbitrary OS command execution with the privileges of the OpenNDS process, typically root. This can result in full system compromise, including data exfiltration, installation of malware, or further lateral movement.
Mitigation
The vulnerability is fixed in OpenNDS version 10.1.3, released on August 28, 2023 [2]. Users should upgrade to this version or later. No workarounds are documented; however, restricting access to the configuration file to only trusted users can reduce the attack surface. This CVE is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of publication.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- OpenNDS/OpenNDSdescription
- osv-coords2 versionspkg:deb/ubuntu/opennds@10.2.0+dfsg-1build2?arch=source&distro=noblepkg:deb/ubuntu/opennds@10.2.0+dfsg-1build2?arch=source&distro=oracular
>= 0+ 1 more
- (no CPE)range: >= 0
- (no CPE)range: >= 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.