Description
Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of service or sensitive information leaking.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update version to G040WQR231013.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-45858 | Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of service or sensitive information leaking. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7505-a0c94-1.html |
|
History
Mon, 14 Oct 2024 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Oct 2024 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-940 |
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-10-14T04:02:18.834Z
Reserved: 2023-08-29T00:14:47.636Z
Link: CVE-2023-41355
Updated: 2024-08-02T19:01:35.278Z
Status : Modified
Published: 2023-11-03T06:15:07.630
Modified: 2024-11-21T08:21:08.403
Link: CVE-2023-41355
No data.
OpenCVE Enrichment
No data.
EUVD