CVE Published: 10/10/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: INCIBE |
Vendor: SHENZHEN REACHFAR TECHNOLOGY COMPANY LIMITED |
Product: Shenzhen Reachfar v28 Status : PUBLISHED
CVE-2023-5499 Description
Information exposure vulnerability in Shenzhen Reachfar v28, the exploitation of which could allow a remote attacker to retrieve all the week\'s logs stored in the \'log2\' directory. An attacker could retrieve sensitive information such as remembered wifi networks, sent messages, SOS device locations and device configurations.
Metrics
CVSS Version: 3.1 |
Base Score: 7.5 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N