PT-2023-27229 · Arris · Arris Dg860A+1

·

CVE-2023-40038

·

Publicado

2023-12-27

·

Atualizado

2024-01-04

CVSS v3.1

8.8

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Arris DG860A (affected versions not specified) Arris DG1670A (affected versions not specified)
Description The devices have predictable default WPA2 PSKs, which could lead to unauthorized remote access. They use the first 6 characters of the SSID and the last 6 characters of the BSSID, decrementing the last digit.
Recommendations For Arris DG860A, change the default WPA2 PSK to a unique and strong password. For Arris DG1670A, change the default WPA2 PSK to a unique and strong password. As a temporary workaround, consider changing the SSID and BSSID to make it harder for attackers to predict the default WPA2 PSK.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-40038

Produtos afetados

Arris Dg1670A
Arris Dg860A