HIGH
An Issue in Buffalo America, Inc
Published Sep 8, 2023
7.5
HIGHCVSS 3.1
EPSS 0.94%
Description
An Issue in Buffalo America, Inc. TeraStation NAS TS5410R v.5.00 thru v.0.07 allows a remote attacker to obtain sensitive information via the guest account function.
Affected products
No data.
AND
- 5.00-0.07
Running on/with
- n/a
-
Affected
- ≥ v.5.00, ≤ v.0.07
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Buffalo America Inc | Terastation Nas Ts5410r | unknown | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-43328 Advisory
- https://github.com/bcross520/bcross520.github.io/wiki/Buffalo-Terastation-NAS-Disabled-guest-built%E2%80%90in-account-allows-for-SMB%5CRPC-device-enumeration Exploit
- https://github.com/bcross520/bcross520.github.io/wiki/Buffalo-Terastation-NAS-Disabled-guest-built%E2%80%90in-account-allows-for-SMB%5CRPC-device-enumeration. Broken Link
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 8, 2023
Updated Sep 26, 2024
Reserved Aug 7, 2023
Link CVE-2023-39620
CISA Vulnrichment
Updated Sep 26, 2024
Red Hat
No data
GitHub
No data