CVE-2023-43757

MEDIUMCVSS 6.5/10EPSS 0.50%

Last modified

CVE-2023-43757 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Inadequate encryption strength vulnerability in multiple routers provided by ELECOM CO.,LTD. and LOGITEC CORPORATION allows a network-adjacent unauthenticated attacker to guess the encryption key used for wireless LAN communication and intercept the communication. EPSS estimates a 0.50% chance of exploitation in the next 30 days.

Description

Inadequate encryption strength vulnerability in multiple routers provided by ELECOM CO.,LTD. and LOGITEC CORPORATION allows a network-adjacent unauthenticated attacker to guess the encryption key used for wireless LAN communication and intercept the communication. As for the affected products/versions, see the information provided by the vendor under [References] section.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.50%

38.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ElecomWrc-2533ghbk2-T FirmwareAll versions
ElecomWrc-2533ghbk-I FirmwareAll versions
ElecomWrc-1750ghbk2-I FirmwareAll versions
ElecomWrc-1750ghbk-E FirmwareAll versions
ElecomWrc-1750ghbk FirmwareAll versions
ElecomWrc-1167ghbk2 FirmwareAll versions
ElecomWrc-1167ghbk FirmwareAll versions
ElecomWrc-F1167acf FirmwareAll versions
ElecomWrc-733ghbk FirmwareAll versions
ElecomWrc-733ghbk-I FirmwareAll versions
ElecomWrc-733ghbk-C FirmwareAll versions
ElecomWrc-300ghbk2-I FirmwareAll versions
ElecomWrc-300ghbk FirmwareAll versions
ElecomWrc-733febk FirmwareAll versions
ElecomWrc-300febk FirmwareAll versions
ElecomWrc-F300nf FirmwareAll versions
ElecomWrh-300wh-H FirmwareAll versions
ElecomWrh-300bk FirmwareAll versions
ElecomWrh-300wh FirmwareAll versions
ElecomWrh-300rd FirmwareAll versions
ElecomWrh-300sv FirmwareAll versions
ElecomWrh-300bk-S FirmwareAll versions
ElecomWrh-300wh-S FirmwareAll versions
ElecomWrh-300bk2-S FirmwareAll versions
ElecomWrh-300wh2-S FirmwareAll versions
ElecomWrh-H300bk FirmwareAll versions
ElecomWrh-H300wh FirmwareAll versions
ElecomWrh-150bk FirmwareAll versions
ElecomWrh-150wh FirmwareAll versions
ElecomLan-W300n\/Rs FirmwareAll versions
ElecomLan-W301nr FirmwareAll versions
ElecomLan-W300n\/P FirmwareAll versions
ElecomLan-Wh300n\/Dgp FirmwareAll versions
ElecomLan-Wh300ndgpe FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-43757?
Inadequate encryption strength vulnerability in multiple routers provided by ELECOM CO.,LTD. and LOGITEC CORPORATION allows a network-adjacent unauthenticated attacker to guess the encryption key used for wireless LAN communication and intercept the communication. As for the affected products/versions, see the information provided by the vendor under [References] section.
How severe is CVE-2023-43757?
CVE-2023-43757 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.50% probability of exploitation in the next 30 days.
How do I fix CVE-2023-43757?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-43757?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST