First published: Tue Apr 11 2023(Updated: )
Stored-cross-site scripting vulnerability in Buffalo network devices allows an attacker with access to the web management console of the product to execute arbitrary JavaScript on a legitimate user's web browser. The affected products and versions are as follows: BS-GS2008 firmware Ver. 1.0.10.01 and earlier, BS-GS2016 firmware Ver. 1.0.10.01 and earlier, BS-GS2024 firmware Ver. 1.0.10.01 and earlier, BS-GS2048 firmware Ver. 1.0.10.01 and earlier, BS-GS2008P firmware Ver. 1.0.10.01 and earlier, BS-GS2016P firmware Ver. 1.0.10.01 and earlier, and BS-GS2024P firmware Ver. 1.0.10.01 and earlier
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Buffalo BS-GS2008P | <=1.0.10.01 | |
Buffalo Bs-gs2008 Firmware | ||
All of | ||
Buffalo BS-GS2016P | <=1.0.10.01 | |
Buffalo BS-GS2016 | ||
All of | ||
Buffalo Bs-gs2024 | <=1.0.10.01 | |
Buffalo Bs-gs2024 | ||
All of | ||
Buffalo Bs-gs2048 Firmware | <=1.0.10.01 | |
Buffalo BS-GS2048 | ||
All of | ||
Buffalo BS-GS2008P | <=1.0.10.01 | |
Buffalo BS-GS2008P | ||
All of | ||
Buffalo BS-GS2016P | <=1.0.10.01 | |
Buffalo Bs-gs2016p Firmware | ||
All of | ||
Buffalo Bs-gs2024 | <=1.0.10.01 | |
Buffalo Bs-gs2024p Firmware | ||
Buffalo BS-GS2008P | <=1.0.10.01 | |
Buffalo Bs-gs2008 Firmware | ||
Buffalo BS-GS2016P | <=1.0.10.01 | |
Buffalo BS-GS2016 | ||
Buffalo Bs-gs2024 | <=1.0.10.01 | |
Buffalo Bs-gs2024 | ||
Buffalo Bs-gs2048 Firmware | <=1.0.10.01 | |
Buffalo BS-GS2048 | ||
Buffalo BS-GS2008P | <=1.0.10.01 | |
Buffalo BS-GS2008P | ||
Buffalo BS-GS2016P | <=1.0.10.01 | |
Buffalo Bs-gs2016p Firmware | ||
Buffalo Bs-gs2024 | <=1.0.10.01 | |
Buffalo Bs-gs2024p Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-24464.
The severity of CVE-2023-24464 is medium.
The affected software of CVE-2023-24464 is Buffalo BS-GS2008 firmware Ver. 1.0.10.01.
An attacker with access to the web management console of the affected Buffalo network devices can exploit CVE-2023-24464 to execute arbitrary JavaScript on a legitimate user's web browser.
To fix CVE-2023-24464, update the Buffalo BS-GS2008 firmware to version 1.0.10.01 or later.