CVE-2023-5142: H3C ER6300G2 Config File userLogin.asp path traversal
A vulnerability classified as problematic was found in H3C GR-1100-P, GR-1108-P, GR-1200W, GR-1800AX, GR-2200, GR-3200, GR-5200, GR-8300, ER2100n, ER2200G2, ER3200G2, ER3260G2, ER5100G2, ER5200G2 and ER6300G2 up to 20230908. This vulnerability affects unknown code of the file /userLogin.asp of the component Config File Handler. The manipulation leads to path traversal. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. VDB-240238 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5142?
The severity of CVE-2023-5142 is medium, with a severity value of 5.3.
What software is affected by CVE-2023-5142?
The following H3C devices are affected by CVE-2023-5142: GR-1100-P, GR-1108-P, GR-1200W, GR-1800AX, GR-2200, GR-3200, GR-5200, GR-8300, ER2100n, ER2200G2, ER3200G2, ER3260G2, ER5100G2, ER5200G2, and ER6300G2.
How can I fix the vulnerability in CVE-2023-5142?
Currently, there is no known fix or patch available for the vulnerability in CVE-2023-5142. It is recommended to monitor the vendor's website for updates or contact them for further instructions.
What is the Common Weakness Enumeration (CWE) of CVE-2023-5142?
The Common Weakness Enumeration (CWE) of CVE-2023-5142 is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')).
Where can I find more information about CVE-2023-5142?
You can find more information about CVE-2023-5142 on the following references: [GitHub](https://github.com/CJCniubi666/H3C-ER/blob/main/README.md), [GitHub](https://github.com/yinsel/CVE-H3C-Report), [VulDB](https://vuldb.com/?ctiid.240238).