PT-2023-24281 · Nec · Aterm Wg1800Hp+15
Published
2023-06-28
·
Updated
2023-07-05
·
CVE-2023-3331
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
NEC Corporation Aterm WG2600HP2 versions all
NEC Corporation Aterm WG2600HP versions all
NEC Corporation Aterm WG2200HP versions all
NEC Corporation Aterm WG1800HP2 versions all
NEC Corporation Aterm WG1800HP versions all
NEC Corporation Aterm WG1400HP versions all
NEC Corporation Aterm WG600HP versions all
NEC Corporation Aterm WG300HP versions all
NEC Corporation Aterm WF300HP versions all
NEC Corporation Aterm WR9500N versions all
NEC Corporation Aterm WR9300N versions all
NEC Corporation Aterm WR8750N versions all
NEC Corporation Aterm WR8700N versions all
NEC Corporation Aterm WR8600N versions all
NEC Corporation Aterm WR8370N versions all
NEC Corporation Aterm WR8175N versions all
NEC Corporation Aterm WR8170N versions all
Description
The issue is related to an Improper Limitation of a Pathname to a Restricted Directory, allowing an attacker to delete specific files in the product.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aterm W300P
Aterm Wg1400Hp
Aterm Wg1800Hp
Aterm Wg1800Hp2
Aterm Wg2200Hp
Aterm Wg2600Hs
Aterm Wg2600Hp2
Aterm Wg600Hp
Aterm Wr8170N
Aterm Wr8175N
Aterm Wr8370N
Aterm Wr8600N
Aterm Wr8700N
Aterm Wr8750N
Aterm Wr9300N
Aterm Wr9500N