2023-09-24 23:55:28 +00:00
{
"id" : "CVE-2023-5142" ,
"sourceIdentifier" : "cna@vuldb.com" ,
"published" : "2023-09-24T22:15:10.087" ,
2024-04-11 02:04:14 +00:00
"lastModified" : "2024-04-11T01:22:53.100" ,
2023-11-07 21:03:21 +00:00
"vulnStatus" : "Modified" ,
2023-09-24 23:55:28 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "A vulnerability classified as problematic was found in H3C GR-1100-P, GR-1108-P, GR-1200W, GR-1800AX, GR-2200, GR-3200, GR-5200, GR-8300, ER2100n, ER2200G2, ER3200G2, ER3260G2, ER5100G2, ER5200G2 and ER6300G2 up to 20230908. This vulnerability affects unknown code of the file /userLogin.asp of the component Config File Handler. The manipulation leads to path traversal. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. VDB-240238 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way."
2023-09-26 22:00:29 +00:00
} ,
{
"lang" : "es" ,
"value" : "Una vulnerabilidad clasificada como problem\u00e1tica fue encontrada en H3C GR-1100-P, GR-1108-P, GR-1200W, GR-1800AX, GR-2200, GR-3200, GR-5200, GR-8300, ER2100n, ER2200G2, ER3200G2 , ER3260G2, ER5100G2, ER5200G2 y ER6300G2 hasta 20230908. Esta vulnerabilidad afecta a c\u00f3digo desconocido del archivo /userLogin.asp del componente Config File Handler. La manipulaci\u00f3n conduce al recorrido del camino. El ataque se puede iniciar de forma remota. La complejidad de un ataque es bastante alta. La explotaci\u00f3n parece dif\u00edcil. El exploit ha sido divulgado al p\u00fablico y puede utilizarse. VDB-240238 es el identificador asignado a esta vulnerabilidad. NOTA: Se contact\u00f3 primeramente con el proveedor sobre esta divulgaci\u00f3n, pero no respondi\u00f3 de ninguna manera."
2023-09-24 23:55:28 +00:00
}
] ,
"metrics" : {
2023-09-26 22:00:29 +00:00
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 5.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 1.4
2023-11-07 21:03:21 +00:00
} ,
2023-09-24 23:55:28 +00:00
{
2024-02-13 09:00:34 +00:00
"source" : "cna@vuldb.com" ,
2023-09-24 23:55:28 +00:00
"type" : "Secondary" ,
"cvssData" : {
2023-11-07 21:03:21 +00:00
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" ,
2023-09-24 23:55:28 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 3.7 ,
"baseSeverity" : "LOW"
} ,
"exploitabilityScore" : 2.2 ,
"impactScore" : 1.4
}
] ,
"cvssMetricV2" : [
{
2024-02-13 09:00:34 +00:00
"source" : "cna@vuldb.com" ,
2023-09-24 23:55:28 +00:00
"type" : "Secondary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:H/Au:N/C:P/I:N/A:N" ,
"accessVector" : "NETWORK" ,
"accessComplexity" : "HIGH" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 2.6
} ,
"baseSeverity" : "LOW" ,
"exploitabilityScore" : 4.9 ,
"impactScore" : 2.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
2023-09-26 22:00:29 +00:00
"source" : "nvd@nist.gov" ,
2023-09-24 23:55:28 +00:00
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-22"
}
]
2023-09-26 22:00:29 +00:00
} ,
{
2024-02-13 09:00:34 +00:00
"source" : "cna@vuldb.com" ,
2023-09-26 22:00:29 +00:00
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-22"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:h3c:gr-1100-p_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "20230908" ,
"matchCriteriaId" : "D840020D-2C49-4208-BA79-9BF9C4EBA4D9"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:h3c:gr-1100-p:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FA2A23D8-5DF5-4647-AB32-AF86E117789F"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:h3c:gr-1108-p_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "20230908" ,
"matchCriteriaId" : "A33D38D0-144E-4576-96F5-D184485EF455"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:h3c:gr-1108-p:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E432A5DB-5D0F-464F-8235-EB9543E3F06A"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:h3c:gr-1200w_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "20230908" ,
"matchCriteriaId" : "94126EC2-0D0B-46F3-8CF6-3E1C42D7D100"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:h3c:gr-1200w:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C4ECDCE3-0655-43A0-A6C5-658E7C4F5470"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:h3c:gr-1800ax_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "20230908" ,
"matchCriteriaId" : "19B18747-B268-45AB-A254-64DCB72C109B"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:h3c:gr-1800ax:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "435BF35B-1867-48E5-BC8C-3F868E9B419B"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:h3c:gr-2200_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "20230908" ,
"matchCriteriaId" : "75F33539-7670-4732-B470-4AB11816E549"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:h3c:gr-2200:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8543B702-DF8C-435F-A39E-56C8043E4321"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:h3c:gr-3200_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "20230908" ,
"matchCriteriaId" : "D94AFA76-7869-4B48-B22B-AAC0AE7D7960"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:h3c:gr-3200:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "945172AA-02BE-4538-952C-3F2EF9749810"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:h3c:gr-5200_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "20230908" ,
"matchCriteriaId" : "0D61370D-1950-4AA3-A6A2-CFE9A199CAE8"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:h3c:gr-5200:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "55A3F347-7936-4966-9C0B-D61CC92BA85A"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:h3c:gr-8300_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "20230908" ,
"matchCriteriaId" : "A545124C-076D-46E7-96B2-4B8CFF2BEFB8"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:h3c:gr-8300:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7AB46F02-E18F-4E67-A941-FE24C06C2CFC"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:h3c:er3260g2_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "20230908" ,
"matchCriteriaId" : "60B2DE7C-598B-4002-BB42-EC2D7E129FBF"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:h3c:er3260g2:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D6504103-D36F-499D-A6CE-1E952477B00F"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:h3c:er5200g2_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "20230908" ,
"matchCriteriaId" : "39FEFC0A-4816-419E-830C-7D2AE5C95EEF"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:h3c:er5200g2:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EC97A451-6C13-4805-BF52-9C424B898636"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:h3c:er3200g2_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "20230908" ,
"matchCriteriaId" : "88AC8D91-BA03-49AC-9FC7-2D3DA30E9D4D"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:h3c:er3200g2:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3126DFD1-B3D2-4F01-BDB6-D22E681E3228"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:h3c:er2100n_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "20230908" ,
"matchCriteriaId" : "28BE8148-9573-4708-B5DE-6ED69AED6993"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:h3c:er2100n:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "803C9117-16A7-4812-A530-82AE6B331147"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:h3c:er6300g2_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "20230908" ,
"matchCriteriaId" : "0A6F28D8-BA6D-497E-95AA-D35052FFBF6F"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:h3c:er6300g2:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3E9CE23F-9941-471E-82CE-0EE150608E04"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:h3c:er5100g2_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "20230908" ,
"matchCriteriaId" : "DFDDB7BA-795A-4853-B3C6-3894DA11E69E"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:h3c:er5100g2:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "11594FE2-E591-4F06-9856-751DCF3F8949"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:h3c:er2200g2_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "20230908" ,
"matchCriteriaId" : "51A4E096-5A31-468B-B84B-9DDA123BEE2F"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:h3c:er2200g2:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3DB4A4EC-8E98-4F3B-B116-925B15A9E5C1"
}
]
}
]
2023-09-24 23:55:28 +00:00
}
] ,
"references" : [
{
"url" : "https://github.com/CJCniubi666/H3C-ER/blob/main/README.md" ,
2023-09-26 22:00:29 +00:00
"source" : "cna@vuldb.com" ,
"tags" : [
"Exploit" ,
"Third Party Advisory"
]
2023-09-24 23:55:28 +00:00
} ,
{
"url" : "https://github.com/yinsel/CVE-H3C-Report" ,
2023-09-26 22:00:29 +00:00
"source" : "cna@vuldb.com" ,
"tags" : [
"Exploit" ,
"Third Party Advisory"
]
2023-09-24 23:55:28 +00:00
} ,
{
"url" : "https://vuldb.com/?ctiid.240238" ,
2023-09-26 22:00:29 +00:00
"source" : "cna@vuldb.com" ,
"tags" : [
"Permissions Required" ,
"Third Party Advisory"
]
2023-09-24 23:55:28 +00:00
} ,
{
"url" : "https://vuldb.com/?id.240238" ,
2023-09-26 22:00:29 +00:00
"source" : "cna@vuldb.com" ,
"tags" : [
"Third Party Advisory"
]
2023-09-24 23:55:28 +00:00
}
]
}