First published: Wed Jun 28 2023(Updated: )
Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all versions allows a attacker to delete specific files in the product.
Credit: psirt-info@cyber.jp.nec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nec Aterm Wf300hp Firmware | ||
Nec Aterm Wf300hp | ||
Nec Aterm Wg1400hp Firmware | ||
Nec Aterm Wg1400hp | ||
Nec Aterm Wg1800hp Firmware | ||
Nec Aterm Wg1800hp | ||
Nec Aterm Wg1800hp2 Firmware | ||
Nec Aterm Wg1800hp2 | ||
Nec Aterm Wg2200hp Firmware | ||
Nec Aterm Wg2200hp | ||
Nec Aterm Wg2600hp Firmware | ||
Nec Aterm Wg2600hp | ||
Nec Aterm Wg2600hp2 Firmware | ||
Nec Aterm Wg2600hp2 | ||
Nec Aterm Wg300hp Firmware | ||
Nec Aterm Wg300hp | ||
Nec Aterm Wg600hp Firmware | ||
Nec Aterm Wg600hp | ||
Nec Aterm Wr8600n Firmware | ||
Nec Aterm Wr8600n | ||
Nec Aterm Wr8700n Firmware | ||
Nec Aterm Wr8700n | ||
Nec Aterm Wr8750n Firmware | ||
Nec Aterm Wr8750n | ||
Nec Aterm Wr9300n Firmware | ||
Nec Aterm Wr9300n | ||
Nec Aterm Wr9500n Firmware | ||
Nec Aterm Wr9500n | ||
Nec Aterm Wr8170n Firmware | ||
Nec Aterm Wr8170n | ||
Nec Aterm Wr8175n Firmware | ||
Nec Aterm Wr8175n | ||
Nec Aterm Wr8370n Firmware | ||
Nec Aterm Wr8370n |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3331 is an improper limitation of a pathname to a restricted directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N, and WR8170N.
The severity of CVE-2023-3331 is medium with a score of 5.4.
The NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N, and WR8170N are affected by CVE-2023-3331.
To fix CVE-2023-3331, it is recommended to apply the latest firmware or software updates provided by NEC Corporation.
You can find more information about CVE-2023-3331 on the NEC Corporation security advisory page at https://jpn.nec.com/security-info/secinfo/nv23-007_en.html