ID

VAR-202312-0313


CVE

CVE-2023-25643


TITLE

ZTE  of  mc801a  firmware and  mc801a1  Command injection vulnerability in firmware

Trust: 0.8

sources: JVNDB: JVNDB-2023-019736

DESCRIPTION

There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnerability to execute arbitrary commands. ZTE of mc801a firmware and mc801a1 Firmware contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. ZTE MC801A is a 5g indoor WiFi router from China ZTE Corporation

Trust: 2.16

sources: NVD: CVE-2023-25643 // JVNDB: JVNDB-2023-019736 // CNVD: CNVD-2023-99635

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2023-99635

AFFECTED PRODUCTS

vendor:ztemodel:mc801ascope:eqversion:mc801a_elisa3_b19

Trust: 1.0

vendor:ztemodel:mc801a1scope:eqversion:mc801a1_elisa1_b04

Trust: 1.0

vendor:ztemodel:mc801a1scope: - version: -

Trust: 0.8

vendor:ztemodel:mc801ascope: - version: -

Trust: 0.8

vendor:ztemodel:mc801a elisa3 b19scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2023-99635 // JVNDB: JVNDB-2023-019736 // NVD: CVE-2023-25643

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2023-25643
value: HIGH

Trust: 1.0

psirt@zte.com.cn: CVE-2023-25643
value: HIGH

Trust: 1.0

NVD: CVE-2023-25643
value: HIGH

Trust: 0.8

CNVD: CNVD-2023-99635
value: HIGH

Trust: 0.6

CNVD: CNVD-2023-99635
severity: HIGH
baseScore: 7.2
vectorString: AV:A/AC:L/AU:M/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: MULTIPLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 4.1
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2023-25643
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

psirt@zte.com.cn: CVE-2023-25643
baseSeverity: HIGH
baseScore: 8.4
vectorString: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.7
impactScore: 6.0
version: 3.1

Trust: 1.0

NVD: CVE-2023-25643
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2023-99635 // JVNDB: JVNDB-2023-019736 // NVD: CVE-2023-25643 // NVD: CVE-2023-25643

PROBLEMTYPE DATA

problemtype:CWE-77

Trust: 1.0

problemtype:Command injection (CWE-77) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2023-019736 // NVD: CVE-2023-25643

PATCH

title:Patch for ZTE MC801A command injection vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/507761

Trust: 0.6

sources: CNVD: CNVD-2023-99635

EXTERNAL IDS

db:NVDid:CVE-2023-25643

Trust: 3.2

db:ZTEid:1032504

Trust: 1.8

db:JVNDBid:JVNDB-2023-019736

Trust: 0.8

db:CNVDid:CNVD-2023-99635

Trust: 0.6

sources: CNVD: CNVD-2023-99635 // JVNDB: JVNDB-2023-019736 // NVD: CVE-2023-25643

REFERENCES

url:https://support.zte.com.cn/support/news/loopholeinfodetail.aspx?newsid=1032504

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2023-25643

Trust: 1.4

sources: CNVD: CNVD-2023-99635 // JVNDB: JVNDB-2023-019736 // NVD: CVE-2023-25643

SOURCES

db:CNVDid:CNVD-2023-99635
db:JVNDBid:JVNDB-2023-019736
db:NVDid:CVE-2023-25643

LAST UPDATE DATE

2024-08-14T14:54:25.291000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2023-99635date:2023-12-22T00:00:00
db:JVNDBid:JVNDB-2023-019736date:2024-01-15T03:18:00
db:NVDid:CVE-2023-25643date:2023-12-18T20:09:13.630

SOURCES RELEASE DATE

db:CNVDid:CNVD-2023-99635date:2023-12-22T00:00:00
db:JVNDBid:JVNDB-2023-019736date:2024-01-15T00:00:00
db:NVDid:CVE-2023-25643date:2023-12-14T08:15:38.357