CVE-2023-42771
Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent unauthenticated attacker who can access the affected product to download configuration files and/or log files, and upload configuration files and/or firmware. They are affected when running in ST(Standalone) mode.
Published:Oct 3, 2023
Last Modified:Nov 21, 2024
EPS:Oct 3, 2023
EPSS Score:0.00028
CVSS Score:8.3
Affected Products
Vendor
Product
Action
Vendor
Furunosystems
Product
Acera 1310
Furunosystems
Acera 1310
Vendor
Furunosystems
Product
Acera 1310 Firmware
Furunosystems
Acera 1310 Firmware
Vendor
Furunosystems
Product
Acera 1320
Furunosystems
Acera 1320
Vendor
Furunosystems
Product
Acera 1320 Firmware
Furunosystems
Acera 1320 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
