Lucene search

K
nvd[email protected]NVD:CVE-2023-36144
HistoryJun 30, 2023 - 11:15 p.m.

CVE-2023-36144

2023-06-3023:15:10
CWE-862
web.nvd.nist.gov
cve-2023-36144
firmware 1.00.54
unauthenticated attacker
backup file
device configuration

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.034 Low

EPSS

Percentile

91.5%

An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration.

Affected configurations

NVD
Node
intelbrassg_2404_mr_firmwareMatch1.00.54
AND
intelbrassg_2404_mrMatch-

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.034 Low

EPSS

Percentile

91.5%

Related for NVD:CVE-2023-36144