First published: Fri Nov 03 2023(Updated: )
Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of service or sensitive information leaking.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Nokia G-040w-q Firmware | =g040wqr201207 | |
NOKIA G-040W-Q |
Update version to G040WQR231013.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-41355.
The severity of CVE-2023-41355 is critical with a CVSS score of 9.8.
The vulnerability occurs due to improper input validation for ICMP redirect messages in the Chunghwa Telecom NOKIA G-040W-Q Firewall function.
An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of service or sensitive information disclosure.
It is recommended to contact Chunghwa Telecom for information on available fixes or mitigations for CVE-2023-41355.