CVE-2023-3331

MEDIUMCVSS 5.4/10EPSS 0.46%

Last modified

CVE-2023-3331 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all versions allows a attacker to delete specific files in the product.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.

Description

Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all versions allows a attacker to delete specific files in the product.

Metrics

CVSS 3.1
5.4/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

EPSS Probability
0.46%

36.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
NecAterm Wf300hp FirmwareAll versions
NecAterm Wg1400hp FirmwareAll versions
NecAterm Wg1800hp FirmwareAll versions
NecAterm Wg1800hp2 FirmwareAll versions
NecAterm Wg2200hp FirmwareAll versions
NecAterm Wg2600hp FirmwareAll versions
NecAterm Wg2600hp2 FirmwareAll versions
NecAterm Wg300hp FirmwareAll versions
NecAterm Wg600hp FirmwareAll versions
NecAterm Wr8600n FirmwareAll versions
NecAterm Wr8700n FirmwareAll versions
NecAterm Wr8750n FirmwareAll versions
NecAterm Wr9300n FirmwareAll versions
NecAterm Wr9500n FirmwareAll versions
NecAterm Wr8170n FirmwareAll versions
NecAterm Wr8175n FirmwareAll versions
NecAterm Wr8370n FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-3331?
Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all versions allows a attacker to delete specific files in the product.
How severe is CVE-2023-3331?
CVE-2023-3331 has a CVSS score of 5.4/10 (MEDIUM severity). The EPSS model estimates a 0.46% probability of exploitation in the next 30 days.
How do I fix CVE-2023-3331?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-3331?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST