PT-2023-27921 · Nokia · Chunghwa Telecom Nokia G-040W-Q

Ta-Lun Yen

·

Published

2023-11-02

·

Updated

2023-11-13

·

CVE-2023-41353

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chunghwa Telecom NOKIA G-040W-Q (affected versions not specified)
Description The issue is related to weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging into the system. This allows the attacker to gain admin access and perform arbitrary system operations or disrupt the service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2023-41353

Affected Products

Chunghwa Telecom Nokia G-040W-Q