CVE-2023-6729
Last modified
CVE-2023-6729 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. Nokia SR OS routers allow read-write access to the entire file system via SFTP or SCP for users configured with "access console." Consequently, a low privilege authenticated user with "access console" can read or replace the router configuration file as well as other files stored in the Compact Flash or SD card without using CLI commands. This type of attack can lead to a compromise or denial of service of the router after the system is rebooted.. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
Nokia SR OS routers allow read-write access to the entire file system via SFTP or SCP for users configured with "access console." Consequently, a low privilege authenticated user with "access console" can read or replace the router configuration file as well as other files stored in the Compact Flash or SD card without using CLI commands. This type of attack can lead to a compromise or denial of service of the router after the system is rebooted.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-6729?
How severe is CVE-2023-6729?
How do I fix CVE-2023-6729?
Are you affected by CVE-2023-6729?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
