Lucene search

K
cve[email protected]CVE-2023-39172
HistoryDec 07, 2023 - 2:15 p.m.

CVE-2023-39172

2023-12-0714:15:07
CWE-319
web.nvd.nist.gov
4
cve-2023-39172
sensitive information
unencrypted transmission
remote attacker
network traffic capture

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

8.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.9%

The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture and modify network traffic.

Affected configurations

NVD
Node
enbwsenec_storage_box_firmwareMatch-
AND
enbwsenec_storage_boxMatchv1
Node
enbwsenec_storage_box_firmwareMatch-
AND
enbwsenec_storage_boxMatchv2
Node
enbwsenec_storage_box_firmwareMatch-
AND
enbwsenec_storage_boxMatchv3

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Storage Box V1",
    "vendor": "SENEC",
    "versions": [
      {
        "status": "affected",
        "version": "V1"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Storage Box V2",
    "vendor": "SENEC",
    "versions": [
      {
        "status": "affected",
        "version": "V2"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Storage Box V3",
    "vendor": "SENEC",
    "versions": [
      {
        "status": "affected",
        "version": "V3"
      }
    ]
  }
]

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

8.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.9%

Related for CVE-2023-39172