Lucene search

K
cve[email protected]CVE-2022-47732
HistoryJan 20, 2023 - 5:15 p.m.

CVE-2022-47732

2023-01-2017:15:10
CWE-916
web.nvd.nist.gov
20
cve-2022-47732
yeastar
n412
n824
configuration panel
unauthenticated attack
backup file
admin hash

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

50.7%

In Yeastar N412 and N824 Configuration Panel 42.x and 45.x, an unauthenticated attacker can create backup file and download it, revealing admin hash, allowing, once cracked, to login inside the Configuration Panel, otherwise, replacing the hash in the archive and restoring it on the device which will change admin password granting access to the device.

Affected configurations

NVD
Node
yeastarn824Match-
AND
yeastarn824_firmwareMatch-
Node
yeastarn412Match-
AND
yeastarn412_firmwareMatch-

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

50.7%

Related for CVE-2022-47732