CVE-2023-24544: High severity buffalo bs-gsl2024 vulnerability
Improper access control vulnerability in Buffalo network devices allows a network-adjacent attacker to obtain specific files of the product. As a result, the product settings may be altered. The affected products and versions are as follows: BS-GSL2024 firmware Ver. 1.10-0.03 and earlier, BS-GSL2016P firmware Ver. 1.10-0.03 and earlier, BS-GSL2016 firmware Ver. 1.10-0.03 and earlier, BS-GS2008 firmware Ver. 1.0.10.01 and earlier, BS-GS2016 firmware Ver. 1.0.10.01 and earlier, BS-GS2024 firmware Ver. 1.0.10.01 and earlier, BS-GS2048 firmware Ver. 1.0.10.01 and earlier, BS-GS2008P firmware Ver. 1.0.10.01 and earlier, BS-GS2016P firmware Ver. 1.0.10.01 and earlier, and BS-GS2024P firmware Ver. 1.0.10.01 and earlier
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-24544?
CVE-2023-24544 is an improper access control vulnerability in Buffalo network devices that allows a network-adjacent attacker to obtain specific files of the product and alter the product settings.
Which Buffalo network devices are affected by CVE-2023-24544?
The affected Buffalo network devices are BS-GSL2024 firmware Ver. 1.10-0.03 and earlier, BS-GSL2016P firmware Ver. 1.10-0.03, BS-GS2008 firmware Ver. 1.0.10.01, BS-GS2016 firmware Ver. 1.0.10.01, BS-GS2024 firmware Ver. 1.0.10.01, BS-GS2048 firmware Ver. 1.0.10.01, BS-GS2008P firmware Ver. 1.0.10.01, BS-GS2016P firmware Ver. 1.0.10.01, BS-GS2024P firmware Ver. 1.0.10.01, BS-GS2016HP firmware up to exclusive 1.1.7.01, and BS-GS2024HP firmware up to exclusive 1.1.7.01.
How severe is CVE-2023-24544?
CVE-2023-24544 has a severity rating of 8.1 (high).
How can I fix CVE-2023-24544?
To fix CVE-2023-24544, update the firmware of the affected Buffalo network devices to a version that is not vulnerable.
Where can I find more information about CVE-2023-24544?
You can find more information about CVE-2023-24544 on the [JVN website](https://jvn.jp/en/vu/JVNVU96824262/) and the [Buffalo website](https://www.buffalo.jp/news/detail/20230310-01.html).