CVE-2023-0345 Vulnerability Details
/
/
/
CVE-2023-0345 Metadata Quick Info
CVE Published: 13/03/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023
Source: icscert |
Vendor: Akuvox |
Product: E11
Status : PUBLISHED
CVE-2023-0345 Description
The Akuvox E11 secure shell (SSH) server is enabled by default and can be accessed by the root user. This password cannot be changed by the user.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
l➤ Exploitability Metrics:
Attack Vector (AV)* NETWORK
Attack Complexity (AC)* LOW
Privileges Required (PR)* NONE
User Interaction (UI)* NONE
Scope (S)* UNCHANGED
l➤ Impact Metrics:
Confidentiality Impact (C)* HIGH
Integrity Impact (I)* HIGH
Availability Impact (A)* HIGH
Weakness Enumeration (CWE)
CWE-ID:
CWE Name: CWE-798 Use of Hard-coded Credentials
Source: Akuvox
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).