Lucene search

K
cveZdiCVE-2023-27370
HistoryMay 03, 2024 - 2:15 a.m.

CVE-2023-27370

2024-05-0302:15:15
CWE-312
zdi
web.nvd.nist.gov
32
netgear rax30
cleartext storage
information disclosure
vulnerability
authentication bypass
configuration secrets
nvd
zdi-can-19841

CVSS3

5.7

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

16.2%

NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.

The specific flaw exists within the handling of device configuration. The issue results from the storage of configuration secrets in plaintext. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19841.

Affected configurations

Vulners
Vulnrichment
Node
netgearrax30Range1.0.9.90
VendorProductVersionCPE
netgearrax30*cpe:2.3:a:netgear:rax30:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "NETGEAR",
    "product": "RAX30",
    "versions": [
      {
        "version": "1.0.9.90_3",
        "status": "affected"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

5.7

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

16.2%

Related for CVE-2023-27370