Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2023-49900: X-Rite MA-T6 Allows Remote Code Execution
CVE-2023-49900 · published 2 months ago
Summary
The X-Rite MA-T6 is at risk of a remote attack that could allow an attacker to execute malicious code. This is a serious issue because it could allow an attacker to take control of the device. To protect yourself, make sure the device is properly updated with the latest security patches.
What to do
- Update x-rite ma-t6 to version v2.33 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| x-rite | ma-t6 | < v2.33 |
Original advisory text
An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.
An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.
References
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-78OS Command Injection
Timeline
Published16 Jul 2026
Updated7 Oct 2026
First seen16 Jul 2026
Track software like this
Free during beta