CRITICAL
Chunghwa Telecom NOKIA G-040W-Q - Excessive Authentication Attempts
Published Nov 3, 2023
9.8
CRITICALCVSS 3.1
EPSS 0.75%
Description
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha check and more susceptible to brute force attacks.
Affected products
-
- Version G040WQR201207StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Chunghwa Telecom | Nokia G-040w-Q | unaffected |
|
AND
- g040wqr201207
-
- Version g040wqr201207StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Nokia | G-040w-Q Firmware | unaffected |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update version to G040WQR231013.
Weaknesses (1)
References (1)
- https://www.twcert.org.tw/tw/cp-132-7500-0c544-1.html Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.twcert.org.tw/tw/cp-132-7500-0c544-1.html | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Nov 3, 2023
Updated Sep 6, 2024
Reserved Aug 29, 2023
Link CVE-2023-41350
CISA Vulnrichment
Updated Sep 5, 2024