ID: CVE-2023-5028

Last Modified: Sept. 20, 2023

A vulnerability, which was classified as problematic, has been found in China Unicom TEWA-800G 4.16L.04_CT2015_Yueme. Affected by this issue is some unknown functionality. The manipulation leads to information exposure through debug log file. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. VDB-239870 is the identifier assigned to this vulnerability.

Twitter Activity

Tweets last week: 0

Remaining steady

Yahoo Activity

Yahoo results: 0

Remaining steady

EPSS History

Current EPSS Score: 0.00052

Remaining steady


Reddit Activity

Reddit Posts: 0

Remaining steady

Github Repos

Github Repos: 0

Remaining steady

Exploits

Found exploits:

Attack Vector: Physical

Attack Complexity: Low

Privileges Required: None

User Interaction: None

Scope: Unchanged

Confidentiality: High

Integrity: None

Availability: None

Base Score: 4.6

Exploitability Score: 0.9

Impact Score: 3.6

CVSS V3: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Specialize CVSS-Score

CWE-532

Condition Configuration
AND
OR
OR
Alle Schwachstellen für chinaunicom
OR
OR
Alle Schwachstellen für chinaunicom
Date: Sept. 20, 2023

CWE-ID: CWE-534
Base Score V3: Not defined
Exploitability Score V3: Not defined
Impact Score V3: Not defined
Cvss Vector V3: Not defined



                    <?xml version="1.0" ?>
<set operator="and">
    <set operator="and">
        <set operator="or">
            <prop key="operating_system" value="cpe:2.3:o:chinaunicom:tewa-800g_firmware:4.16l.04_ct2015_yueme:*:*:*:*:*:*:*"/>
        </set>
        <set operator="or">
            <prop key="device" value="cpe:2.3:h:chinaunicom:tewa-800g:-:*:*:*:*:*:*:*"/>
        </set>
    </set>
</set>

                  
                      <?xml version="1.0" ?>
<set operator="and">
    <set operator="and">
        <set operator="or">
            <prop key="operating_system" value="cpe:2.3:o:chinaunicom:tewa-800g_firmware:4.16l.04_ct2015_yueme:*:*:*:*:*:*:*"/>
        </set>
        <set operator="or">
            <prop key="device" value="cpe:2.3:h:chinaunicom:tewa-800g:-:*:*:*:*:*:*:*"/>
        </set>
    </set>
    <prop key="program_influence" value="input"/>
</set>