| ID | 
        
          CVE-2023-42128
         | 
      
      
          | Sažetak | 
        Magnet Forensics AXIOM Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Magnet Forensics AXIOM. User interaction is required to exploit this vulnerability in that the target must acquire data from a malicious mobile device.
The specific flaw exists within the Android device image acquisition functionality. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-21255. | 
      
      
          | Reference | 
        
          
         | 
      
      
        | CVSS | 
        
          
              | Base:           | 8.0 |  
              | Impact:         | 5.9 |  
              | Exploitability: | 2.1 |  
           
         | 
      
    
        | Pristup | 
        
        
            | Vektor | Složenost | Autentikacija |  
            
            | ADJACENT_NETWORK | 
            LOW | 
            NONE | 
             
         
         | 
    
      
        | Impact | 
        
        
            | Povjerljivost | Cjelovitost | Dostupnost |  
            
            | HIGH | 
            HIGH | 
            HIGH | 
             
         
         | 
    
    
        | CVSS vektor | 
        CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 
      
      
          | Zadnje važnije ažuriranje | 
          
            18-08-2025 - 15:32 | 
          
      
      
          | Objavljeno | 
          
            03-05-2024 - 03:15 |