CVE-2023-43134: Critical severity netis systems 360r firmware vulnerability
Published Sep 20, 2023
·Updated
There is an unauthorized access vulnerability in Netis 360RAC1200 v1.3.4517, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to the device backend management.
Affected Software
2 affected components
netis-systems 360r Firmware=1.3.4517
netis-systems 360r
Event History
Sep 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the unauthorized access vulnerability in Netis 360RAC1200 v1.3.4517?
The vulnerability ID is CVE-2023-43134.
2
What is the severity level of CVE-2023-43134?
The severity level of CVE-2023-43134 is critical with a score of 9.8 out of 10.
3
What is the affected software version of CVE-2023-43134?
The affected software version of CVE-2023-43134 is Netis 360RAC1200 v1.3.4517.
4
How does the unauthorized access vulnerability in Netis 360RAC1200 v1.3.4517 allow attackers to obtain sensitive information?
The vulnerability allows attackers to obtain sensitive information of the device without authentication.
5
Is there a fix available for CVE-2023-43134?
To fix the vulnerability, users should update to a version of the firmware that is not affected by the vulnerability.