CVE-2023-22389: Medium severity snap one wattbox wb-300-ip-3 vulnerability
Published Jan 30, 2023
·Updated
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior store passwords in a plaintext file when the device configuration is exported via Save/Restore–>Backup Settings, which could be read by any user accessing the file.
Affected Software
3 affected components
Snap One Wattbox WB-300-IP-3: versions WB10.9a17 and prior
Snapav Wattbox Wb-300-ip-3 Firmware<=wb10.9a17
Snapav Wattbox Wb-300-ip-3
Remediation
Information
Snap One has released the following updates for the affected products:
* Version WB10.B929 https://app.ovrc.com/#/user-settings (login required)
Event History
Jan 30, 2023
CVE Published
via MITRE·10:06 PM
Data Sourced
via MITRE·10:06 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-22389.
2
What is the severity of CVE-2023-22389?
CVE-2023-22389 has a severity rating of medium (6.5).
3
Which versions of Snap One Wattbox WB-300-IP-3 are affected by CVE-2023-22389?
Versions WB10.9a17 and prior of Snap One Wattbox WB-300-IP-3 are affected by CVE-2023-22389.
4
How does CVE-2023-22389 store passwords?
CVE-2023-22389 stores passwords in a plaintext file when the device configuration is exported via Save/Restore–>Backup Settings.
5
Who can read the plaintext password file in CVE-2023-22389?
Any user accessing the file can read the plaintext passwords in CVE-2023-22389.