Lucene search

K
cveMitreCVE-2023-30350
HistoryMay 29, 2023 - 12:15 a.m.

CVE-2023-30350

2023-05-2900:15:09
mitre
web.nvd.nist.gov
19
cve-2023-30350
fs s3900-24t4s
privilege escalation
admin password reset
nvd

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.003

Percentile

71.0%

FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin password.

Affected configurations

Nvd
Node
fss3900_24t4sMatch-
AND
fss3900_24t4s_firmwareMatch-
VendorProductVersionCPE
fss3900_24t4s-cpe:2.3:h:fs:s3900_24t4s:-:*:*:*:*:*:*:*
fss3900_24t4s_firmware-cpe:2.3:o:fs:s3900_24t4s_firmware:-:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.003

Percentile

71.0%