← Back

CVE-2023-26588

nvd nist
Published: Apr 11, 2023Modified: Feb 11, 2025

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Use of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to access the debug function of the product. The affected products and versions are as follows: BS-GSL2024 firmware Ver. 1.10-0.03 and earlier, BS-GSL2016P firmware Ver. 1.10-0.03 and earlier, BS-GSL2016 firmware Ver. 1.10-0.03 and earlier, BS-GS2008 firmware Ver. 1.0.10.01 and earlier, BS-GS2016 firmware Ver. 1.0.10.01 and earlier, BS-GS2024 firmware Ver. 1.0.10.01 and earlier, BS-GS2048 firmware Ver. 1.0.10.01 and earlier, BS-GS2008P firmware Ver. 1.0.10.01 and earlier, BS-GS2016P firmware Ver. 1.0.10.01 and earlier, and BS-GS2024P firmware Ver. 1.0.10.01 and earlier

Affected (18)

16 products
Bs Gsl2024 Firmware
Bs Gsl2016p Firmware
Bs Gsl2016 Firmware
Bs Gs2008 Firmware
Bs Gs2016 Firmware
Bs Gs2024 Firmware
Bs Gs2048 Firmware
Bs Gs2008p Firmware
Bs Gs2016p Firmware
Bs Gs2024p Firmware
Bs Gsl2005 Firmware
Bs Gsl2008 Firmware
Bs Gsl2005p Firmware
Bs Gsl2008p Firmware
Bs Gs2016hp Firmware
Bs Gs2024hp Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.10-0.03
Running on/withPlatform Versions
Buffalo
Bs Gsl2024
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.10-0.03
Running on/withPlatform Versions
Buffalo
Bs Gsl2016p
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.10-0.03
Running on/withPlatform Versions
Buffalo
Bs Gsl2016
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.10.01
Running on/withPlatform Versions
Buffalo
Bs Gs2008
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.10.01
Running on/withPlatform Versions
Buffalo
Bs Gs2016
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.10.01
Running on/withPlatform Versions
Buffalo
Bs Gs2024
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.10.01
Running on/withPlatform Versions
Buffalo
Bs Gs2048
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.10.01
Running on/withPlatform Versions
Buffalo
Bs Gs2008p
All versions
Configuration I
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.0.10.01
Configuration J
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.0.10.01
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.12-0.01
Running on/withPlatform Versions
Buffalo
Bs Gsl2005
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.12-0.01
Running on/withPlatform Versions
Buffalo
Bs Gsl2008
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.11-0.01
Running on/withPlatform Versions
Buffalo
Bs Gsl2005p
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.11-0.01
Running on/withPlatform Versions
Buffalo
Bs Gsl2008p
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.7.01
Running on/withPlatform Versions
Buffalo
Bs Gs2016p
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.7.01
Running on/withPlatform Versions
Buffalo
Bs Gs2016hp
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.7.01
Running on/withPlatform Versions
Buffalo
Bs Gs2024p
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.7.01
Running on/withPlatform Versions
Buffalo
Bs Gs2024hp
All versions

References (4)

Source: vultures@jpcert.or.jp
PatchThird Party Advisory
Source: vultures@jpcert.or.jp
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.