CVE-2023-41921
A vulnerability allows attackers to download source code or an executable from a remote location and execute the code without sufficiently verifying the origin and integrity of the code. This vulnerability can allow attackers to modify the firmware before uploading it to the system, thus achieving the modification of the target’s integrity to achieve an insecure state.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.13%
- CWE
- CWE-494
- Published
- 2024-07-02
- Last modified
- 2026-03-13
Affected products
- Kiloview P1/P2
Weakness type
Related vulnerabilities
- CVE-2025-68109 — ChurchCRM vulnerable to RCE with database restore functionality
- CVE-2025-15556 — Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification
- CVE-2026-3502 — TrueConf Client Update Integrity Verification Bypass
- CVE-2026-3000 — Changing|IDExpert Windows Logon Agent - Remote Code Execution
- CVE-2026-2999 — Changing|IDExpert Windows Logon Agent - Remote Code Execution
- CVE-2024-28878 — IOSIX IO-1020 Micro ELD Download of Code Without Integrity Check
- CVE-2026-33075 — FastGPT has Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-image.yml
- CVE-2025-53696 — iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the