ID

VAR-202407-2516


CVE

CVE-2024-41688


TITLE

syrotech  of  sy-gpon-1110-wdont  Vulnerability related to plaintext storage of important information in firmware

Trust: 0.8

sources: JVNDB: JVNDB-2024-004956

DESCRIPTION

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext credentials on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system. syrotech of sy-gpon-1110-wdont The firmware contains a vulnerability related to plaintext storage of sensitive information.Information may be obtained. SyroTech SY-GPON-1110-WDONT is a wireless router from SyroTech

Trust: 2.16

sources: NVD: CVE-2024-41688 // JVNDB: JVNDB-2024-004956 // CNVD: CNVD-2024-34375

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2024-34375

AFFECTED PRODUCTS

vendor:syrotechmodel:sy-gpon-1110-wdontscope: - version: -

Trust: 1.4

vendor:syrotechmodel:sy-gpon-1110-wdontscope:eqversion:3.1.02-231102

Trust: 1.0

vendor:syrotechmodel:sy-gpon-1110-wdontscope:eqversion:sy-gpon-1110-wdont firmware 3.1.02-231102

Trust: 0.8

vendor:syrotechmodel:sy-gpon-1110-wdontscope:eqversion: -

Trust: 0.8

sources: CNVD: CNVD-2024-34375 // JVNDB: JVNDB-2024-004956 // NVD: CVE-2024-41688

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2024-41688
value: MEDIUM

Trust: 1.0

vdisclose@cert-in.org.in: CVE-2024-41688
value: HIGH

Trust: 1.0

NVD: CVE-2024-41688
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2024-34375
value: HIGH

Trust: 0.6

CNVD: CNVD-2024-34375
severity: HIGH
baseScore: 8.3
vectorString: AV:A/AC:L/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2024-41688
baseSeverity: MEDIUM
baseScore: 4.6
vectorString: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 0.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2024-41688
baseSeverity: MEDIUM
baseScore: 4.6
vectorString: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2024-34375 // JVNDB: JVNDB-2024-004956 // NVD: CVE-2024-41688 // NVD: CVE-2024-41688

PROBLEMTYPE DATA

problemtype:CWE-312

Trust: 1.0

problemtype:Plaintext storage of important information (CWE-312) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-004956 // NVD: CVE-2024-41688

PATCH

title:Patch for SyroTech SY-GPON-1110-WDONT Information Disclosure Vulnerability (CNVD-2024-34375)url:https://www.cnvd.org.cn/patchInfo/show/575476

Trust: 0.6

sources: CNVD: CNVD-2024-34375

EXTERNAL IDS

db:NVDid:CVE-2024-41688

Trust: 3.2

db:JVNDBid:JVNDB-2024-004956

Trust: 0.8

db:CNVDid:CNVD-2024-34375

Trust: 0.6

sources: CNVD: CNVD-2024-34375 // JVNDB: JVNDB-2024-004956 // NVD: CVE-2024-41688

REFERENCES

url:https://www.cert-in.org.in/s2cmainservlet?pageid=pubvlnotes01&vlcode=civn-2024-0225

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2024-41688

Trust: 1.4

sources: CNVD: CNVD-2024-34375 // JVNDB: JVNDB-2024-004956 // NVD: CVE-2024-41688

SOURCES

db:CNVDid:CNVD-2024-34375
db:JVNDBid:JVNDB-2024-004956
db:NVDid:CVE-2024-41688

LAST UPDATE DATE

2024-08-15T12:48:41.087000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2024-34375date:2024-08-02T00:00:00
db:JVNDBid:JVNDB-2024-004956date:2024-08-07T00:41:00
db:NVDid:CVE-2024-41688date:2024-08-05T21:05:46.433

SOURCES RELEASE DATE

db:CNVDid:CNVD-2024-34375date:2024-08-02T00:00:00
db:JVNDBid:JVNDB-2024-004956date:2024-08-07T00:00:00
db:NVDid:CVE-2024-41688date:2024-07-26T12:15:03.370