First published: Fri Nov 03 2023(Updated: )
Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated remote attacker can exploit this vulnerability by sending a crafted package, resulting in partially sensitive information exposed to an actor.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Nokia G-040w-q Firmware | =g040wqr201207 | |
NOKIA G-040W-Q |
Update version to G040WQR231013.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-41354.
The title of the vulnerability is Chunghwa Telecom NOKIA G-040W-Q - Exposure of Sensitive Information.
The vulnerability allows an unauthenticated remote attacker to partially expose sensitive information by exploiting the Chunghwa Telecom NOKIA G-040W-Q Firewall function's failure to block ICMP TIMESTAMP requests by default.
The Nokia G-040w-q Firmware with version g040wqr201207 is affected.
The severity of the vulnerability is medium (4 out of 10).