Hardcoded Cryptographic Key Vulnerability in VR-S1000 Firmware by Buffalo
CVE-2023-46711

4.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
26 December 2023

What is CVE-2023-46711?

The VR-S1000 firmware versions prior to 2.37 are vulnerable due to the use of a hardcoded cryptographic key. This design flaw presents an opportunity for attackers to potentially decipher user passwords, compromising the security of affected systems. Users of VR-S1000 firmware are urged to upgrade to the latest version to mitigate the risks associated with this vulnerability.

Affected Version(s)

VR-S1000 firmware Ver. 2.37 and earlier

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.