PT-2023-6357 · Connectize · Connectize Ac21000 G6
Published
2023-10-19
·
Updated
2024-08-27
·
CVE-2023-24049
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Connectize AC21000 G6 version 641.139.1.1256
Description
An issue was discovered that allows attackers to gain escalated privileges on the device via poor credential management. This is related to weak password requirements. Exploitation of the issue may allow a remote attacker to obtain administrator privileges.
Recommendations
For version 641.139.1.1256, consider changing the password management settings to enforce stronger credentials until a patch is available. As a temporary workaround, restrict access to the device to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Connectize Ac21000 G6