← Back

CVE-2023-24022

nvd nist
Published: Jan 26, 2023Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded credentials that are easily discovered and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)

Affected (2)

2 products
Rtd Firmware
Rts Firmware
Configuration A
2 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Before 3.7.11.6
Before 3.7.11.6
Running on/withPlatform Versions
Baicells
Nova227
All versions
Baicells
Nova233
All versions
Baicells
Nova243
All versions

References (6)

Source: security@baicells.com
Release NotesVendor Advisory
Source: security@baicells.com
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.