PT-2023-8177 · Eurotel · Eurotel Etl3100
Gjoko Krstic
·
Published
2023-12-19
·
Updated
2023-12-29
·
CVE-2023-6930
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
EuroTel ETL3100 versions v01c01 and v01x37
Description
The issue is related to an unauthenticated configuration and log download vulnerability. This vulnerability enables an attacker to disclose sensitive information, which can assist in authentication bypass, privilege escalation, and ultimately, full system access. Additionally, the vulnerability is associated with a lack of authentication attempt limits, allowing a remote attacker to gain full access through brute force.
Recommendations
For EuroTel ETL3100 versions v01c01 and v01x37, consider restricting access to configuration and log download features to minimize the risk of exploitation.
As a temporary workaround, avoid using the vulnerable configuration and log download functionality until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eurotel Etl3100