CVE Database
/

CVE-2023-5142

Back to search

CVE-2023-5142

Published: Sep 24, 2023

Modified: Aug 2, 2024

PUBLISHED

CVSS v3.1

3.7

LOW

Description

A vulnerability classified as problematic was found in H3C GR-1100-P, GR-1108-P, GR-1200W, GR-1800AX, GR-2200, GR-3200, GR-5200, GR-8300, ER2100n, ER2200G2, ER3200G2, ER3260G2, ER5100G2, ER5200G2 and ER6300G2 up to 20230908. This vulnerability affects unknown code of the file /userLogin.asp of the component Config File Handler. The manipulation leads to path traversal. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. VDB-240238 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

VendorProductVersions

H3C

GR-1100-P

affected
20230908

H3C

GR-1108-P

affected
20230908

H3C

GR-1200W

affected
20230908

H3C

GR-1800AX

affected
20230908

H3C

GR-2200

affected
20230908

H3C

GR-3200

affected
20230908

H3C

GR-5200

affected
20230908

H3C

GR-8300

affected
20230908

H3C

ER2100n

affected
20230908

H3C

ER2200G2

affected
20230908

H3C

ER3200G2

affected
20230908

H3C

ER3260G2

affected
20230908

H3C

ER5100G2

affected
20230908

H3C

ER5200G2

affected
20230908

H3C

ER6300G2

affected
20230908

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now