CVE-2023-24838

HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the administrator's credential. This credential can then be used to login PowerStation or Secure Shell to achieve remote code execution.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hgiga:powerstation_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hgiga:powerstation:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:48

Type Values Removed Values Added
References () https://www.twcert.org.tw/tw/cp-132-6957-d8f67-1.html - Third Party Advisory () https://www.twcert.org.tw/tw/cp-132-6957-d8f67-1.html - Third Party Advisory

15 May 2023, 03:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 9.8
Summary HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the administrator’s credential, resulting in performing arbitrary system operation or disrupt service. HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the administrator's credential. This credential can then be used to login PowerStation or Secure Shell to achieve remote code execution.
CWE CWE-306 CWE-200

30 Mar 2023, 19:24

Type Values Removed Values Added
First Time Hgiga powerstation Firmware
Hgiga powerstation
Hgiga
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 7.5
References (CONFIRM) https://www.twcert.org.tw/tw/cp-132-6957-d8f67-1.html - (CONFIRM) https://www.twcert.org.tw/tw/cp-132-6957-d8f67-1.html - Third Party Advisory
CWE CWE-200 CWE-306
CPE cpe:2.3:h:hgiga:powerstation:-:*:*:*:*:*:*:*
cpe:2.3:o:hgiga:powerstation_firmware:*:*:*:*:*:*:*:*

27 Mar 2023, 05:15

Type Values Removed Values Added
Summary HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the administrator’s credential, resulting in performing arbitrary system operation or disrupt service. HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the administrator’s credential, resulting in performing arbitrary system operation or disrupt service.

27 Mar 2023, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-27 04:15

Updated : 2024-11-21 07:48


NVD link : CVE-2023-24838

Mitre link : CVE-2023-24838

CVE.ORG link : CVE-2023-24838


JSON object : View

Products Affected

hgiga

  • powerstation
  • powerstation_firmware
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-306

Missing Authentication for Critical Function