CVE-2023-41355: Chunghwa Telecom NOKIA G-040W-Q - Improper Input Validation
Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of service or sensitive information leaking.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-41355.
What is the severity of CVE-2023-41355?
The severity of CVE-2023-41355 is critical with a CVSS score of 9.8.
How does the Chunghwa Telecom NOKIA G-040W-Q Firewall function vulnerability occur?
The vulnerability occurs due to improper input validation for ICMP redirect messages in the Chunghwa Telecom NOKIA G-040W-Q Firewall function.
What can an unauthenticated remote attacker do with this vulnerability?
An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of service or sensitive information disclosure.
Is there a fix available for CVE-2023-41355?
It is recommended to contact Chunghwa Telecom for information on available fixes or mitigations for CVE-2023-41355.