PT-2023-32138 · Unknown · Shenzhen Reachfar

Joel Serna Moreno

·

Publicado

2023-10-10

·

Atualizado

2023-12-19

·

CVE-2023-5499

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Shenzhen Reachfar version v28
Description The issue allows a remote attacker to retrieve all the week's logs stored in the 'log2' directory, potentially exposing sensitive information such as remembered wifi networks, sent messages, SOS device locations, and device configurations.
Recommendations For Shenzhen Reachfar version v28, consider restricting access to the 'log2' directory as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-5499

Produtos afetados

Shenzhen Reachfar