Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent unauthenticated attacker who can access the affected product to download configuration files and/or log files, and upload configuration files and/or firmware. They are affected when running in ST(Standalone) mode.
History

Fri, 20 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-288
CPEs cpe:2.3:o:furunosystems:acera_1310_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:furunosystems:acera_1320_firmware:-:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2023-10-03T00:17:00.358Z

Updated: 2024-09-20T13:36:28.745Z

Reserved: 2023-09-22T04:36:33.436Z

Link: CVE-2023-42771

cve-icon Vulnrichment

Updated: 2024-08-02T19:30:24.335Z

cve-icon NVD

Status : Modified

Published: 2023-10-03T01:15:56.967

Modified: 2024-09-20T14:35:09.807

Link: CVE-2023-42771

cve-icon Redhat

No data.