{"id":"DEBIAN-CVE-2023-42810","details":"systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem was fixed with a parameter check in version 5.21.7. As a workaround, check or sanitize parameter strings that are passed to `wifiConnections()`, `wifiNetworks()` (string only).","modified":"2026-06-01T20:00:37.453699087Z","published":"2023-09-21T18:15:12.327Z","withdrawn":"2026-06-01T20:00:37.453698939Z","upstream":["CVE-2023-42810"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-42810"}],"affected":[{"package":{"name":"node-systeminformation","ecosystem":"Debian:14","purl":"pkg:deb/debian/node-systeminformation?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.31.6-1","5.31.6-2","5.31.6-3","5.31.6-4","5.31.7-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-42810.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}