CVE-2023-45599
Ailux Imx6 ≤ 1.0.7-2
Raw vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:LSummary
CVE-2023-45599 is a medium-severity Reliance on File Name or Extension of Externally-Supplied File (CWE-646) vulnerability in Ailux Imx6. Its CVSS base score is 5.5 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Double File Extension (T1036.007); ranked at the 12th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SI-10 (Information Input Validation) and SI-3 (Malicious Code Protection) — see the control section below for these in your framework.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-49891
Vulnerability Data
A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web application allows a remote authenticated attacker to upload any arbitrary type of file into the device. This issue affects: AiLux imx6…
more
bundle below version imx6_1.0.7-2.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V5.1.1
Mitigating Controls (NIST 800-53 r5) AI
Requires validation of information inputs, which structurally stops reliance on untrusted file names or extensions by forcing content-based checks.
Malicious-code protection at entry points blocks dangerous file types from being accepted and executed.
Least functionality restricts the file types and automatic processing capabilities the system will accept.
Mobile-code controls define, authorize, and block unacceptable uploaded code before automatic processing occurs.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Restricting execution of unauthorized software directly blocks dangerous uploaded files from running.
Secure SDLC practices directly require content-based validation instead of trusting file extensions for externally supplied files.
Hardened configuration baselines can enforce allowed file types and processing rules.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect the weakness, but the control does not guarantee its elimination.
Restricting software installation can limit dangerous file types but does not enforce content-based validation.
Web filtering can block risky file extensions but does not address server-side file handling logic.
Secure SDLC requires proper file-type validation, directly mitigating reliance on untrusted names or extensions.
Application security requirements can mandate content inspection, but the control itself does not prescribe the technique.
Secure architecture principles encourage safe file handling, yet the control is broader than this specific weakness.