2023-08-23 23:55:33 +00:00
{
"id" : "CVE-2023-3453" ,
"sourceIdentifier" : "ics-cert@hq.dhs.gov" ,
"published" : "2023-08-23T22:15:08.930" ,
2023-12-28 21:00:29 +00:00
"lastModified" : "2023-12-28T19:26:17.687" ,
2023-09-01 20:00:28 +00:00
"vulnStatus" : "Analyzed" ,
2023-08-23 23:55:33 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "\nETIC Telecom RAS versions 4.7.0 and prior the web management portal authentication disabled by default. This could allow an attacker with adjacent network access to alter the configuration of the device or cause a denial-of-service condition.\n\n"
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-09-01 20:00:28 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" ,
"attackVector" : "ADJACENT_NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 8.1 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 5.2
} ,
2023-08-23 23:55:33 +00:00
{
"source" : "ics-cert@hq.dhs.gov" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L" ,
"attackVector" : "ADJACENT_NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "LOW" ,
"baseScore" : 7.1 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 3.7
}
]
} ,
"weaknesses" : [
{
"source" : "ics-cert@hq.dhs.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-1188"
}
]
}
] ,
2023-09-01 20:00:28 +00:00
"configurations" : [
{
2023-12-28 21:00:29 +00:00
"operator" : "AND" ,
2023-09-01 20:00:28 +00:00
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
2023-12-28 21:00:29 +00:00
"criteria" : "cpe:2.3:o:etictelecom:remote_access_server_firmware:*:*:*:*:*:*:*:*" ,
2023-09-01 20:00:28 +00:00
"versionEndIncluding" : "4.7.0" ,
2023-12-28 21:00:29 +00:00
"matchCriteriaId" : "418E040C-258B-4D39-AF47-62E801FF6D9A"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:etictelecom:ras-c-100-lw:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5DAE45DD-78EE-4ACB-A1E5-C190BE642BDF"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:etictelecom:ras-e-100:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "93F02AE2-6AC3-492E-9E91-E9F0725A1EEB"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:etictelecom:ras-e-220:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C32ED13F-237B-441C-8032-F54615AEFC73"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:etictelecom:ras-e-400:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "86536932-B27A-4028-829D-2924CD431C54"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:etictelecom:ras-ec-220-lw:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "52E2D325-0AE3-4459-9F27-5CC19349F060"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:etictelecom:ras-ec-400-lw:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DB8D1AA9-42C0-4546-A02E-91B3D7A8AD4B"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:etictelecom:ras-ec-480-lw:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "50EEA797-3218-44FE-8D93-178C40F4BF17"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:etictelecom:ras-ecw-220-lw:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E768A79E-BBFD-47C1-8535-1F721D92575C"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:etictelecom:ras-ecw-400-lw:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F1D86798-3C5F-40A9-BF41-0602F78A027B"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:etictelecom:ras-ew-100:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D12CC48E-6DAC-4412-9068-04B774540500"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:etictelecom:ras-ew-220:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7D7A25F4-412A-4D16-922F-1219B86E31A0"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:etictelecom:ras-ew-400:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "32675A39-A1B3-4773-902A-6E6F8A72D16D"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:etictelecom:rfm-e:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B7543976-5400-4A9E-8E62-CB65FD00D0E1"
2023-09-01 20:00:28 +00:00
}
]
}
]
}
] ,
2023-08-23 23:55:33 +00:00
"references" : [
{
"url" : "https://www.cisa.gov/news-events/ics-advisories/icsa-23-208-01" ,
2023-09-01 20:00:28 +00:00
"source" : "ics-cert@hq.dhs.gov" ,
"tags" : [
"Patch" ,
"Third Party Advisory" ,
"US Government Resource"
]
2023-08-23 23:55:33 +00:00
}
]
}