First published: Fri Apr 14 2023(Updated: )
An issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download functionality does not check the session cookie. Thus, an attacker can download all log files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Commscope Dg3450 Firmware | =ar01.02.056.18_041520_711.ncs.10 | |
Commscope Dg3450 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-27571 is medium with a severity value of 5.3.
The affected software of CVE-2023-27571 is Commscope Dg3450 Firmware version ar01.02.056.18_041520_711.ncs.10.
An attacker can exploit CVE-2023-27571 by downloading all log files through the troubleshooting_logs_download.php log file download functionality without checking the session cookie.
Currently, there are no known fixes or patches available for CVE-2023-27571. It is recommended to contact the vendor for more information.
The Common Weakness Enumeration (CWE) ID associated with CVE-2023-27571 is CWE-306.