CVE-2023-26588
Use of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to access the debug function of the product.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Use of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to access the debug function of the product. The affected products and versions are as follows: BS-GSL2024 firmware Ver. 1.10-0.03 and earlier, BS-GSL2016P firmware Ver. 1.10-0.03 and earlier, BS-GSL2016 firmware Ver. 1.10-0.03 and earlier, BS-GS2008 firmware Ver. 1.0.10.01 and earlier, BS-GS2016 firmware Ver. 1.0.10.01 and earlier, BS-GS2024 firmware Ver. 1.0.10.01 and earlier, BS-GS2048 firmware Ver. 1.0.10.01 and earlier, BS-GS2008P firmware Ver. 1.0.10.01 and earlier, BS-GS2016P firmware Ver. 1.0.10.01 and earlier, and BS-GS2024P firmware Ver. 1.0.10.01 and earlier
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.57% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-668
- Affected
- buffalo/bs-gsl2024 firmware · buffalo/bs-gsl2016p firmware · buffalo/bs-gsl2016 firmware · buffalo/bs-gs2008 firmware · buffalo/bs-gs2016 firmware · buffalo/bs-gs2024 firmware · buffalo/bs-gs2048 firmware · buffalo/bs-gs2008p firmware · buffalo/bs-gs2016p firmware · buffalo/bs-gs2024p firmware · buffalo/bs-gsl2005 firmware · buffalo/bs-gsl2008 firmware · buffalo/bs-gsl2005p firmware · buffalo/bs-gsl2008p firmware · buffalo/bs-gs2016hp firmware · buffalo/bs-gs2024hp firmware
- Source
- vultures@jpcert.or.jp
References
- https://jvn.jp/en/vu/JVNVU96824262/Patch, Third Party Advisory
- https://www.buffalo.jp/news/detail/20230310-01.htmlVendor Advisory
- https://jvn.jp/en/vu/JVNVU96824262/Patch, Third Party Advisory
- https://www.buffalo.jp/news/detail/20230310-01.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.