ID

VAR-202309-0474


CVE

CVE-2023-40039


DESCRIPTION

An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame

Trust: 0.99

sources: NVD: CVE-2023-40039 // VULMON: CVE-2023-40039

AFFECTED PRODUCTS

vendor:arrismodel:tg852gscope:eqversion: -

Trust: 1.0

vendor:arrismodel:tg862gscope:eqversion: -

Trust: 1.0

vendor:arrismodel:tg1672gscope:eqversion: -

Trust: 1.0

sources: NVD: CVE-2023-40039

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2023-40039
value: CRITICAL

Trust: 1.0

nvd@nist.gov: CVE-2023-40039
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: NVD: CVE-2023-40039

PROBLEMTYPE DATA

problemtype:CWE-284

Trust: 1.0

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2023-40039

EXTERNAL IDS

db:NVDid:CVE-2023-40039

Trust: 1.1

db:VULMONid:CVE-2023-40039

Trust: 0.1

sources: VULMON: CVE-2023-40039 // NVD: CVE-2023-40039

REFERENCES

url:https://i.ebayimg.com/images/g/-ucaaoswde1kyd-z/s-l1600.png

Trust: 1.1

url:https://i.ebayimg.com/images/g/4p0aaoswdhxkrztt/s-l1600.jpg

Trust: 1.1

url:https://github.com/actuator/cve/blob/main/arris/cve-2023-40039

Trust: 1.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2023-40039 // NVD: CVE-2023-40039

SOURCES

db:VULMONid:CVE-2023-40039
db:NVDid:CVE-2023-40039

LAST UPDATE DATE

2024-09-27T23:12:14.972000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2023-40039date:2023-09-11T00:00:00
db:NVDid:CVE-2023-40039date:2024-09-26T16:35:16.887

SOURCES RELEASE DATE

db:VULMONid:CVE-2023-40039date:2023-09-11T00:00:00
db:NVDid:CVE-2023-40039date:2023-09-11T07:15:08.123