← Back

CVE-2023-24544

nvd nist
Published: Apr 11, 2023Modified: Feb 11, 2025

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD

Description

Improper access control vulnerability in Buffalo network devices allows a network-adjacent attacker to obtain specific files of the product. As a result, the product settings may be altered. The affected products and versions are as follows: BS-GSL2024 firmware Ver. 1.10-0.03 and earlier, BS-GSL2016P firmware Ver. 1.10-0.03 and earlier, BS-GSL2016 firmware Ver. 1.10-0.03 and earlier, BS-GS2008 firmware Ver. 1.0.10.01 and earlier, BS-GS2016 firmware Ver. 1.0.10.01 and earlier, BS-GS2024 firmware Ver. 1.0.10.01 and earlier, BS-GS2048 firmware Ver. 1.0.10.01 and earlier, BS-GS2008P firmware Ver. 1.0.10.01 and earlier, BS-GS2016P firmware Ver. 1.0.10.01 and earlier, and BS-GS2024P firmware Ver. 1.0.10.01 and earlier

Affected (14)

12 products
Bs Gsl2024 Firmware
Bs Gsl2016p Firmware
Bs Gsl2016 Firmware
Bs Gs2008 Firmware
Bs Gs2016 Firmware
Bs Gs2024 Firmware
Bs Gs2048 Firmware
Bs Gs2008p Firmware
Bs Gs2016p Firmware
Bs Gs2024p Firmware
Bs Gs2016hp Firmware
Bs Gs2024hp Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.10-0.03
Running on/withPlatform Versions
Buffalo
Bs Gsl2024
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.10-0.03
Running on/withPlatform Versions
Buffalo
Bs Gsl2016p
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.10-0.03
Running on/withPlatform Versions
Buffalo
Bs Gsl2016
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.10.01
Running on/withPlatform Versions
Buffalo
Bs Gs2008
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.10.01
Running on/withPlatform Versions
Buffalo
Bs Gs2016
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.10.01
Running on/withPlatform Versions
Buffalo
Bs Gs2024
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.10.01
Running on/withPlatform Versions
Buffalo
Bs Gs2048
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.10.01
Running on/withPlatform Versions
Buffalo
Bs Gs2008p
All versions
Configuration I
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.0.10.01
Configuration J
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.0.10.01
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.7.01
Running on/withPlatform Versions
Buffalo
Bs Gs2016p
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.7.01
Running on/withPlatform Versions
Buffalo
Bs Gs2016hp
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.7.01
Running on/withPlatform Versions
Buffalo
Bs Gs2024p
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.7.01
Running on/withPlatform Versions
Buffalo
Bs Gs2024hp
All versions

References (4)

Source: vultures@jpcert.or.jp
Third Party Advisory
Source: vultures@jpcert.or.jp
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.