CVE-2023-1327
Published Mar 14, 2023
Last updated 2 years ago
Overview
- Description
- Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerability, allowing an unauthenticated attacker to gain administrative access to the device's web management interface by resetting the admin password.
- Source
- vulnreport@tenable.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Weaknesses
- nvd@nist.gov
- CWE-287
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:netgear:rax30:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "EBC92B49-60E0-4554-BE7F-D2B5D6EF6454" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:netgear:rax30_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5DA843E4-41CF-48B1-8AFD-4267BE3EEF40", "versionEndExcluding": "1.0.6.74" } ], "operator": "OR" } ], "operator": "AND" } ]