CVE-2023-36144
intelbras sg_2404_mr_firmware Missing Authorization
Record summary
CVE-2023-36144 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration.
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
sg_2404_mrBrowse intelbras / sg_2404_mrDefault status: unknown | CVE List | 1.00.54 | affected |
sg_2404_mr_firmwareBrowse intelbras / sg_2404_mr_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubleonardobg/CVE-2023-36144Repository PoCby leonardobgStars: 1Not analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHIntelbras Switch - Information DisclosureCVSS 7.5
An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration.
Impact
Unauthenticated attackers can exploit authentication bypass to download backup configuration files containing critical device information including credentials and network configuration from Intelbras Switch devices.
Remediation
Apply the latest security patches or updates provided by the vendor to mitigate this vulnerability.
Source: ProjectDiscovery