CVE-2023-39429
Last modified
CVE-2023-39429 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Cross-site scripting vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to inject an arbitrary script via a crafted configuration. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and earlier, ACERA 1150i firmware ver.01.35 and earlier, ACERA 1150w firmware ver.01.35 and earlier, ACERA 1110 firmware ver.01.76 and earlier, ACERA 1020 firmware ver.01.86 and earlier, ACERA 1010 firmware ver.01.86 and earlier, ACERA 950 firmware ver.01.60 and earlier, ACERA 850F firmware ver.01.60 and earlier, ACERA 900 firmware ver.02.54 and earlier, ACERA 850M firmware ver.02.06 and earlier, ACERA 810 firmware ver.03.74 and earlier, and ACERA 800ST firmware ver.07.35 and earlier. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
Cross-site scripting vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to inject an arbitrary script via a crafted configuration. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and earlier, ACERA 1150i firmware ver.01.35 and earlier, ACERA 1150w firmware ver.01.35 and earlier, ACERA 1110 firmware ver.01.76 and earlier, ACERA 1020 firmware ver.01.86 and earlier, ACERA 1010 firmware ver.01.86 and earlier, ACERA 950 firmware ver.01.60 and earlier, ACERA 850F firmware ver.01.60 and earlier, ACERA 900 firmware ver.02.54 and earlier, ACERA 850M firmware ver.02.06 and earlier, ACERA 810 firmware ver.03.74 and earlier, and ACERA 800ST firmware ver.07.35 and earlier. They are affected when running in ST(Standalone) mode.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Furunosystems | Acera 1210 Firmware | <= 02.36 |
| Furunosystems | Acera 1150i Firmware | <= 01.35 |
| Furunosystems | Acera 1150w Firmware | <= 01.35 |
| Furunosystems | Acera 1110 Firmware | <= 01.76 |
| Furunosystems | Acera 1020 Firmware | <= 01.86 |
| Furunosystems | Acera 1010 Firmware | <= 01.86 |
| Furunosystems | Acera 950 Firmware | <= 01.60 |
| Furunosystems | Acera 850f Firmware | <= 01.60 |
| Furunosystems | Acera 900 Firmware | <= 02.54 |
| Furunosystems | Acera 850m Firmware | <= 02.06 |
| Furunosystems | Acera 810 Firmware | <= 03.74 |
| Furunosystems | Acera 800st Firmware | <= 07.35 |
References
- https://jvn.jp/en/vu/JVNVU94497038/Third Party Advisory
- https://jvn.jp/en/vu/JVNVU94497038/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-39429?
How severe is CVE-2023-39429?
How do I fix CVE-2023-39429?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-39421The RDPWin.dll component as used in the IRM Next Generation …7.7
- CVE-2023-39422The /irmdata/api/ endpoints exposed by the IRM Next Generati…9.8
- CVE-2023-39423The RDPData.dll file exposes the /irmdata/api/common endpoin…9.1
- CVE-2023-39424A vulnerability in RDPngFileUpload.dll, as used in the IRM N…8.8
- CVE-2023-39425Improper access control in some Intel(R) DSA software before…7.8
- CVE-2023-39427 In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt …7.8
- CVE-2023-3943Stack-based Buffer Overflow vulnerability in ZkTeco-based OE…10
- CVE-2023-39431 Sante DICOM Viewer Pro lacks proper validation of user-su…7.8
- CVE-2023-39432Improper access control element in some Intel(R) Ethernet to…7.8
- CVE-2023-39433Improper access control for some Intel(R) CST software befor…4.4
- CVE-2023-39434A use-after-free issue was addressed with improved memory ma…8.8
- CVE-2023-39435Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220…9.8
Are you affected by CVE-2023-39429?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
