5.3

CVE-2023-38523

Exploit

The web interface on multiple Samsung Harman AMX N-Series devices allows directory listing for the /tmp/ directory, without authentication, exposing sensitive information such as the command history and screenshot of the file being processed. This affects N-Series N1115 Wallplate Video Encoder before 1.15.61, N-Series N1x22A Video Encoder/Decoder before 1.15.61, N-Series N1x33A Video Encoder/Decoder before 1.15.61, N-Series N1x33 Video Encoder/Decoder before 1.15.61, N-Series N2x35 Video Encoder/Decoder before 1.15.61, N-Series N2x35A Video Encoder/Decoder before 1.15.61, N-Series N2xx2 Video Encoder/Decoder before 1.15.61, N-Series N2xx2A Video Encoder/Decoder before 1.15.61, N-Series N3000 Video Encoder/Decoder before 2.12.105, and N-Series N4321 Audio Transceiver before 1.00.06.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SamsungFgn1115-wp-wh Firmware Version < 1.15.61
   SamsungFgn1115-wp-wh Version-
SamsungFgn1122-sa Firmware Version < 1.15.61
   SamsungFgn1122-sa Version-
SamsungFgn1122-cd Firmware Version < 1.15.61
   SamsungFgn1122-cd Version-
SamsungFgn1222-sa Firmware Version < 1.15.61
   SamsungFgn1222-sa Version-
SamsungFgn1222-cd Firmware Version < 1.15.61
   SamsungFgn1222-cd Version-
SamsungFgn1233-sa Firmware Version < 1.15.61
   SamsungFgn1233-sa Version-
SamsungFgn1133-sa Firmware Version < 1.15.61
   SamsungFgn1133-sa Version-
SamsungFgn1133-cd Firmware Version < 1.15.61
   SamsungFgn1133-cd Version-
SamsungFgn1233-cd Firmware Version < 1.15.61
   SamsungFgn1233-cd Version-
SamsungFgn1133a-sa Firmware Version < 1.15.61
   SamsungFgn1133a-sa Version-
SamsungFgn1233a-sa Firmware Version < 1.15.61
   SamsungFgn1233a-sa Version-
SamsungFgn1133a-cd Firmware Version < 1.15.61
   SamsungFgn1133a-cd Version-
SamsungFgn1233a-cd Firmware Version < 1.15.61
   SamsungFgn1233a-cd Version-
SamsungFgn2135-sa Firmware Version < 1.15.61
   SamsungFgn2135-sa Version-
SamsungFgn2235-cd Firmware Version < 1.15.61
   SamsungFgn2235-cd Version-
SamsungFgn2235-sa Firmware Version < 1.15.61
   SamsungFgn2235-sa Version-
SamsungFgn2135-cd Firmware Version < 1.15.61
   SamsungFgn2135-cd Version-
SamsungFgn2122-sa Firmware Version < 1.15.61
   SamsungFgn2122-sa Version-
SamsungFgn2222-sa Firmware Version < 1.15.61
   SamsungFgn2222-sa Version-
SamsungFgn2212-sa Firmware Version < 1.15.61
   SamsungFgn2212-sa Version-
SamsungFgn2122-cd Firmware Version < 1.15.61
   SamsungFgn2122-cd Version-
SamsungFgn2222-cd Firmware Version < 1.15.61
   SamsungFgn2222-cd Version-
SamsungFgn2212-cd Firmware Version < 1.15.61
   SamsungFgn2212-cd Version-
SamsungFgn2222a-sa Firmware Version < 1.15.61
   SamsungFgn2222a-sa Version-
SamsungFgn2122a-sa Firmware Version < 1.15.61
   SamsungFgn2122a-sa Version-
SamsungFgn2122a-cd Firmware Version < 1.15.61
   SamsungFgn2122a-cd Version-
SamsungFgn2222a-cd Firmware Version < 1.15.61
   SamsungFgn2222a-cd Version-
SamsungFgn3132a-sa Firmware Version < 2.12.105
   SamsungFgn3132a-sa Version-
SamsungFgn3132a-c Firmware Version < 2.12.105
   SamsungFgn3132a-c Version-
SamsungFgn3232a-sa Firmware Version < 2.12.105
   SamsungFgn3232a-sa Version-
SamsungFgn3232a-c Firmware Version < 2.12.105
   SamsungFgn3232a-c Version-
SamsungFgn4321-sa Firmware Version < 1.00.06
   SamsungFgn4321-sa Version-
SamsungFgn4321-cd Firmware Version < 1.00.06
   SamsungFgn4321-cd Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.491
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.