Lucene search

K
cvelistCERT-InCVELIST:CVE-2024-2257
HistoryMay 10, 2024 - 1:26 p.m.

CVE-2024-2257 Password Policy Bypass Vulnerability in Digisol Router

2024-05-1013:26:08
CWE-20
CERT-In
www.cve.org
cve-2024-2257
digisol router
password policy
bypass vulnerability
physical access
security standards
firmware version 3.2.02
hardware version 3.7l

6.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to improper implementation of password policies. An attacker with physical access could exploit this by creating password that do not adhere to the defined security standards/policy on the vulnerable system.

Successful exploitation of this vulnerability could allow the attacker to expose the router to potential security threats.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Digisol Router DG-GR1321",
    "vendor": "Digisol",
    "versions": [
      {
        "status": "affected",
        "version": "v3.2.02"
      }
    ]
  }
]

6.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for CVELIST:CVE-2024-2257