PT-2023-1297 · Tp Link · Tp-Link Sg105Pe
Baba Takao
·
Published
2023-01-11
·
Updated
2025-04-04
·
CVE-2023-22303
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TP-Link SG105PE versions prior to 1.0 1.0.0 Build 20221208
Description
The issue is related to an authentication bypass vulnerability in the firmware of TP-Link SG105PE switches. This vulnerability is associated with weaknesses in the authentication procedure, which can be exploited by a remote attacker to bypass the authentication process. Under certain conditions, an attacker may impersonate an administrator of the product, potentially allowing them to obtain information and/or alter the product's settings with administrative privileges.
Recommendations
For versions prior to 1.0 1.0.0 Build 20221208, update the firmware to a version that is 1.0 1.0.0 Build 20221208 or later to resolve the issue. As a temporary workaround, consider restricting access to the switch's administrative interface until the update can be applied.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tp-Link Sg105Pe