Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2023-49900: X-Rite MA-T6 Allows Remote Code Execution

CVE-2023-49900 · published 2 months ago
Summary

The X-Rite MA-T6 is at risk of a remote attack that could allow an attacker to execute malicious code. This is a serious issue because it could allow an attacker to take control of the device. To protect yourself, make sure the device is properly updated with the latest security patches.

What to do
  • Update x-rite ma-t6 to version v2.33 or later.
Affected software
VendorProductAffected versions
x-rite ma-t6 < v2.33
Original advisory text
An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.
An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-78OS Command Injection
Timeline
Published16 Jul 2026
Updated7 Oct 2026
First seen16 Jul 2026
Sources
CVE-2023-49900 · MITRE
Track software like this
Free during beta