Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all versions allows a attacker to obtain specific files in the product.

Project Subscriptions

Vendors Products
Aterm Wf300hp Subscribe
Aterm Wf300hp Firmware Subscribe
Aterm Wg1400hp Subscribe
Aterm Wg1400hp Firmware Subscribe
Aterm Wg1800hp Subscribe
Aterm Wg1800hp2 Subscribe
Aterm Wg1800hp2 Firmware Subscribe
Aterm Wg1800hp Firmware Subscribe
Aterm Wg2200hp Subscribe
Aterm Wg2200hp Firmware Subscribe
Aterm Wg2600hp Subscribe
Aterm Wg2600hp2 Subscribe
Aterm Wg2600hp2 Firmware Subscribe
Aterm Wg2600hp Firmware Subscribe
Aterm Wg300hp Subscribe
Aterm Wg300hp Firmware Subscribe
Aterm Wg600hp Subscribe
Aterm Wg600hp Firmware Subscribe
Aterm Wr8170n Subscribe
Aterm Wr8170n Firmware Subscribe
Aterm Wr8175n Subscribe
Aterm Wr8175n Firmware Subscribe
Aterm Wr8370n Subscribe
Aterm Wr8370n Firmware Subscribe
Aterm Wr8600n Subscribe
Aterm Wr8600n Firmware Subscribe
Aterm Wr8700n Subscribe
Aterm Wr8700n Firmware Subscribe
Aterm Wr8750n Subscribe
Aterm Wr8750n Firmware Subscribe
Aterm Wr9300n Subscribe
Aterm Wr9300n Firmware Subscribe
Aterm Wr9500n Subscribe
Aterm Wr9500n Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-43998 Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all versions allows a attacker to obtain specific files in the product.
Fixes

Solution

No solution given by the vendor.


Workaround

Stop using the products or remove the USB storage.

History

Wed, 04 Dec 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: NEC

Published:

Updated: 2024-12-04T21:42:54.798Z

Reserved: 2023-06-20T01:14:05.654Z

Link: CVE-2023-3330

cve-icon Vulnrichment

Updated: 2024-08-02T06:55:00.699Z

cve-icon NVD

Status : Modified

Published: 2023-06-28T02:15:49.523

Modified: 2024-11-21T08:17:01.777

Link: CVE-2023-3330

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses