PT-2023-25454 · Intelbras · Intelbras Switch Sg 2404 Mr

Leonardobg

·

Published

2023-06-30

·

Updated

2023-07-10

·

CVE-2023-36144

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Intelbras Switch SG 2404 MR version 1.00.54
Description The issue is related to an authentication bypass that allows an unauthenticated attacker to download the device's backup file, exposing critical configuration information.
Recommendations For Intelbras Switch SG 2404 MR version 1.00.54, consider restricting access to the backup file download functionality until a patch is available.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-36144

Affected Products

Intelbras Switch Sg 2404 Mr