{ "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", "CVE_data_meta": { "ID": "CVE-2024-4231", "ASSIGNER": "vdisclose@cert-in.org.in", "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", "value": "This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to presence of root terminal access on a serial interface without proper access control. An\u00a0attacker\u00a0with\u00a0physical\u00a0access\u00a0could exploit this by identifying UART pins and accessing the root shell on the vulnerable system.\n\nSuccessful exploitation of this vulnerability could allow the attacker to access the sensitive information on the targeted system." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-1191: On-Chip Debug and Test Interface With Improper Access Control", "cweId": "CWE-1191" } ] } ] }, "affects": { "vendor": { "vendor_data": [ { "vendor_name": "Digisol", "product": { "product_data": [ { "product_name": "Digisol Router DG-GR1321", "version": { "version_data": [ { "version_affected": "=", "version_value": "v3.2.02" } ] } } ] } } ] } }, "references": { "reference_data": [ { "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0158", "refsource": "MISC", "name": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0158" } ] }, "generator": { "engine": "Vulnogram 0.2.0" }, "source": { "discovery": "UNKNOWN" }, "solution": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Upgrade Digisol Router firmware to version v3.1.02-240311.
https://www.digisol.com/firmware/
" } ], "value": "Upgrade Digisol Router firmware to version v3.1.02-240311.\n https://www.digisol.com/firmware/" } ], "credits": [ { "lang": "en", "value": "This vulnerability is discovered by Shravan Singh, Ganesh Bakare and Karan Patel from Redfox Cyber Security Inc, Toronto, Canada." } ] }