6.5
CVE-2023-43757
- EPSS 0.5%
- Veröffentlicht 16.11.2023 07:15:08
- Zuletzt bearbeitet 21.11.2024 08:24:43
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
Inadequate encryption strength vulnerability in multiple routers provided by ELECOM CO.,LTD. and LOGITEC CORPORATION allows a network-adjacent unauthenticated attacker to guess the encryption key used for wireless LAN communication and intercept the communication. As for the affected products/versions, see the information provided by the vendor under [References] section.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Elecom ≫ Wrc-2533ghbk2-t Firmware Version-
Elecom ≫ Wrc-2533ghbk-i Firmware Version-
Elecom ≫ Wrc-1750ghbk2-i Firmware Version-
Elecom ≫ Wrc-1750ghbk-e Firmware Version-
Elecom ≫ Wrc-1750ghbk Firmware Version-
Elecom ≫ Wrc-1167ghbk2 Firmware Version-
Elecom ≫ Wrc-1167ghbk Firmware Version-
Elecom ≫ Wrc-f1167acf Firmware Version-
Elecom ≫ Wrc-733ghbk Firmware Version-
Elecom ≫ Wrc-733ghbk-i Firmware Version-
Elecom ≫ Wrc-733ghbk-c Firmware Version-
Elecom ≫ Wrc-300ghbk2-i Firmware Version-
Elecom ≫ Wrc-300ghbk Firmware Version-
Elecom ≫ Wrc-733febk Firmware Version-
Elecom ≫ Wrc-300febk Firmware Version-
Elecom ≫ Wrc-f300nf Firmware Version-
Elecom ≫ Wrh-300wh-h Firmware Version-
Elecom ≫ Wrh-300bk Firmware Version-
Elecom ≫ Wrh-300wh Firmware Version-
Elecom ≫ Wrh-300rd Firmware Version-
Elecom ≫ Wrh-300sv Firmware Version-
Elecom ≫ Wrh-300bk-s Firmware Version-
Elecom ≫ Wrh-300wh-s Firmware Version-
Elecom ≫ Wrh-300bk2-s Firmware Version-
Elecom ≫ Wrh-300wh2-s Firmware Version-
Elecom ≫ Wrh-h300bk Firmware Version-
Elecom ≫ Wrh-h300wh Firmware Version-
Elecom ≫ Wrh-150bk Firmware Version-
Elecom ≫ Wrh-150wh Firmware Version-
Elecom ≫ Lan-w300n/rs Firmware Version-
Elecom ≫ Lan-w301nr Firmware Version-
Elecom ≫ Lan-w300n/p Firmware Version-
Elecom ≫ Lan-wh300n/dgp Firmware Version-
Elecom ≫ Lan-wh300ndgpe Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.5% | 0.385 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-326 Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
https://www.elecom.co.jp/news/security/20210706-01/
https://www.elecom.co.jp/news/security/20230810-01/
https://www.elecom.co.jp/news/security/20231114-01/
https://jvn.jp/en/vu/JVNVU94119876/