Use of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to alter?configuration settings of the device
Published Dec 7, 2022
6.5
MEDIUMCVSS 3.1
EPSS 0.25%
Description
Use of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to alter?configuration settings of the device. The affected products/versions are as follows: WZR-300HP firmware Ver. 2.00 and earlier, WZR-450HP firmware Ver. 2.00 and earlier, WZR-600DHP firmware Ver. 2.00 and earlier, WZR-900DHP firmware Ver. 1.15 and earlier, HW-450HP-ZWE firmware Ver. 2.00 and earlier, WZR-450HP-CWT firmware Ver. 2.00 and earlier, WZR-450HP-UB firmware Ver. 2.00 and earlier, WZR-600DHP2 firmware Ver. 1.15 and earlier, and WZR-D1100H firmware Ver. 2.00 and earlier.
Affected products
-
- Version WZR-300HP firmware Ver. 2.00 and earlier, WZR-450HP firmware Ver. 2.00 and earlier, WZR-600DHP firmware Ver. 2.00 and earlier, WZR-900DHP firmware Ver. 1.15 and earlier, HW-450HP-ZWE firmware Ver. 2.00 and earlier, WZR-450HP-CWT firmware Ver. 2.00 and earlier, WZR-450HP-UB firmware Ver. 2.00 and earlier, WZR-600DHP2 firmware Ver. 1.15 and earlier, and WZR-D1100H firmware Ver. 2.00 and earlier.StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Buffalo Inc. | Buffalo network devices | n/a |
|
Configuration 1
- ≤ 2.00
Configuration 2
- ≤ 2.00
Configuration 3
- ≤ 2.00
Running on/with
- n/a
Configuration 4
- ≤ 1.15
Running on/with
- n/a
Configuration 5
- ≤ 2.00
Running on/with
- n/a
Configuration 6
- ≤ 2.00
Running on/with
- n/a
Configuration 7
- ≤ 2.00
Running on/with
- n/a
Configuration 8
- ≤ 1.15
Running on/with
- n/a
Configuration 9
- ≤ 2.00
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-37746 Advisory
- https://jvn.jp/en/vu/JVNVU92805279/index.html Third Party Advisory
- https://www.buffalo.jp/news/detail/20221003-01.html PatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-37746 | Advisory | |
| https://jvn.jp/en/vu/JVNVU92805279/index.html | Third Party Advisory | |
| https://www.buffalo.jp/news/detail/20221003-01.html | PatchVendor Advisory |
Change history (0)
No recorded changes yet.