2023-11-03 07:00:22 +00:00
{
"id" : "CVE-2023-41353" ,
"sourceIdentifier" : "twcert@cert.org.tw" ,
"published" : "2023-11-03T06:15:07.417" ,
2023-11-13 21:00:21 +00:00
"lastModified" : "2023-11-13T19:31:44.943" ,
"vulnStatus" : "Analyzed" ,
2023-11-03 07:00:22 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging system, resulting in admin access and performing arbitrary system operations or disrupt service."
2023-11-03 15:00:23 +00:00
} ,
{
"lang" : "es" ,
"value" : "Chunghwa Telecom NOKIA G-040W-Q tiene una vulnerabilidad de requisitos de contrase\u00f1a d\u00e9biles. Un atacante remoto con privilegios de usuario normal puede inferir f\u00e1cilmente la contrase\u00f1a del administrador a partir de la informaci\u00f3n del sistema despu\u00e9s de iniciar sesi\u00f3n, lo que da como resultado acceso de administrador y realiza operaciones arbitrarias en el sistema o interrumpe el servicio."
2023-11-03 07:00:22 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-11-13 21:00:21 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 8.8 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 5.9
} ,
2023-11-03 07:00:22 +00:00
{
"source" : "twcert@cert.org.tw" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 8.8 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
2023-11-13 21:00:21 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-521"
}
]
} ,
2023-11-03 07:00:22 +00:00
{
"source" : "twcert@cert.org.tw" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-521"
}
]
}
] ,
2023-11-13 21:00:21 +00:00
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:nokia:g-040w-q_firmware:g040wqr201207:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B44938DD-B7A2-4D58-8B61-AE64C62A3E83"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:nokia:g-040w-q:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B61B9373-5B22-4C83-9781-FCFEB29BB3DB"
}
]
}
]
}
] ,
2023-11-03 07:00:22 +00:00
"references" : [
{
"url" : "https://www.twcert.org.tw/tw/cp-132-7503-a27ed-1.html" ,
2023-11-13 21:00:21 +00:00
"source" : "twcert@cert.org.tw" ,
"tags" : [
"Third Party Advisory"
]
2023-11-03 07:00:22 +00:00
}
]
}