CVE-2023-7237: Lantronix XPort Weak Encoding for Password
Published Jan 23, 2024
·Updated
Lantronix XPort sends weakly encoded credentials within web request headers.
Affected Software
2 affected components
All of the following
Lantronix Xport Edge Firmware=2.0.0.13
Lantronix XPort EDGE
Event History
Jan 23, 2024
CVE Published
via MITRE·09:46 PM
Data Sourced
via MITRE·09:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-7237?
CVE-2023-7237 is classified as a high-severity vulnerability due to its potential impact on credential confidentiality.
2
How do I fix CVE-2023-7237?
To fix CVE-2023-7237, update the firmware of the Lantronix XPort to a newer version that addresses this vulnerability.
3
What types of credentials are involved in CVE-2023-7237?
CVE-2023-7237 involves weakly encoded credentials that are sent within web request headers.
4
Which software versions are affected by CVE-2023-7237?
CVE-2023-7237 affects Lantronix XPort Edge firmware version 2.0.0.13.
5
What impact does CVE-2023-7237 have on users?
CVE-2023-7237 may allow attackers to intercept and exploit weakly encoded credentials, compromising user security.