CVE-2024-36475 Vulnerability Details

  /     /     /  

CVE-2024-36475 Metadata Quick Info

CVE Published: 17/07/2024 | CVE Updated: 02/08/2024 | CVE Year: 2024
Source: jpcert | Vendor: Century Systems Co., Ltd. | Product: FutureNet NXR-1300 series
Status : PUBLISHED

CVE-2024-36475 Description

FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user who knows how to use the debug function logs in to the product, the debug function may be used and an arbitrary OS command may be executed.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Active debug code
Source: Century Systems Co., Ltd.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).