CVE-2023-31728
Last modified
CVE-2023-31728 is a high-severity vulnerability rated 7/10 on the CVSS scale. Teltonika RUT240 devices with firmware before 07.04.2, when bridge mode is used, sometimes make SSH and HTTP services available on the IPv6 WAN interface even though the UI shows that they are only available on the LAN interface.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Teltonika RUT240 devices with firmware before 07.04.2, when bridge mode is used, sometimes make SSH and HTTP services available on the IPv6 WAN interface even though the UI shows that they are only available on the LAN interface.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Teltonika-Networks | Rut240 Firmware | < 00.07.04.2 |
References
- https://research.exoticsilicon.com/articles/lte_ethernet_bridge_bug_followupThird Party Advisory
- https://research.exoticsilicon.com/newsThird Party Advisory
- https://research.exoticsilicon.com/articles/lte_ethernet_bridge_bug_followupThird Party Advisory
- https://research.exoticsilicon.com/newsThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-31728?
How severe is CVE-2023-31728?
How do I fix CVE-2023-31728?
Are you affected by CVE-2023-31728?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
