Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Gianpiero Costantino

Researcher fromNational Cybersecurity Agency (ACN)
#22042of 53,633
10.6Total CVSS
Vulnerabilities · 2
Low
1
High
1
PT-2024-15061
3.3
2024-10-17
Nokia · Nokia Sr Os · CVE-2023-6728
**Name of the Vulnerable Software and Affected Versions** Nokia SR OS (affected versions not specified) **Description** The Nokia SR OS bof.cfg file encryption is vulnerable to a brute force attack, allowing an attacker in possession of the encrypted file to decrypt it and obtain the BOF configuration content. This weakness can lead to sensitive data exposure. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-15062
7.3
2024-10-17
Nokia · Nokia Sr Os · CVE-2023-6729
**Name of the Vulnerable Software and Affected Versions** Nokia SR OS routers (affected versions not specified) **Description** The issue allows low-privilege authenticated users with "access console" to gain read-write access to the entire file system via SFTP or SCP. This access enables them to read or replace the router configuration file and other files stored in the Compact Flash or SD card without using CLI commands, potentially leading to a compromise or denial of service of the router after a system reboot. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.