Description
Improper Neutralization of Input During Web Page Generation vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all versions allows a attacker to 

execute an arbitrary script, after obtaining a high privilege exploiting CVE-2023-3330 and CVE-2023-3331 vulnerabilities.
Published: 2023-06-28
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

Stop using the products or remove the USB storage.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-44000 Improper Neutralization of Input During Web Page Generation vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all versions allows a attacker to  execute an arbitrary script, after obtaining a high privilege exploiting CVE-2023-3330 and CVE-2023-3331 vulnerabilities.
History

Wed, 04 Dec 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Nec Aterm Wf300hp Aterm Wf300hp Firmware Aterm Wg1400hp Aterm Wg1400hp Firmware Aterm Wg1800hp Aterm Wg1800hp2 Aterm Wg1800hp2 Firmware Aterm Wg1800hp Firmware Aterm Wg2200hp Aterm Wg2200hp Firmware Aterm Wg2600hp Aterm Wg2600hp2 Aterm Wg2600hp2 Firmware Aterm Wg2600hp Firmware Aterm Wg300hp Aterm Wg300hp Firmware Aterm Wg600hp Aterm Wg600hp Firmware Aterm Wr8170n Aterm Wr8170n Firmware Aterm Wr8175n Aterm Wr8175n Firmware Aterm Wr8370n Aterm Wr8370n Firmware Aterm Wr8600n Aterm Wr8600n Firmware Aterm Wr8700n Aterm Wr8700n Firmware Aterm Wr8750n Aterm Wr8750n Firmware Aterm Wr9300n Aterm Wr9300n Firmware Aterm Wr9500n Aterm Wr9500n Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: NEC

Published:

Updated: 2024-12-04T20:52:34.092Z

Reserved: 2023-06-20T01:14:10.138Z

Link: CVE-2023-3332

cve-icon Vulnrichment

Updated: 2024-08-02T06:55:01.051Z

cve-icon NVD

Status : Modified

Published: 2023-06-28T02:15:49.650

Modified: 2024-11-21T08:17:02.127

Link: CVE-2023-3332

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses