PT-2023-6356 · Connectize · Connectize Ac21000 G6

CVE-2023-24047

·

Publicado

2023-10-19

·

Atualizado

2024-08-27

CVSS v3.1

8.0

Alta

VetorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Connectize AC21000 G6 version 641.139.1.1256
Description The issue is related to insecure credential management, allowing attackers to gain escalated privileges via the use of a weak hashing algorithm. It also involves a vulnerability in the administrative web interface of the Connectize G6 AC2100 router's firmware, due to the failure to neutralize special elements used in the operating system command. This could allow a remote attacker to disclose protected information.
Recommendations For version 641.139.1.1256, consider disabling the use of weak hashing algorithms as a temporary workaround until a patch is available. Restrict access to the administrative web interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Incorrect Authorization

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07068
CVE-2023-24047

Produtos afetados

Connectize Ac21000 G6