cert-in.org.inThird-party advisory
https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225 CVE-2024-41686
HIGH
Password Policy Bypass Vulnerability
Record summary
CVE-2024-41686 has a selected CVSS score of 7.3 (high).
Description
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to improper implementation of password policies. A local attacker could exploit this by creating password that do not adhere to the defined security standards/policy on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to expose the router to potential security threats.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 26, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
SyroTech SY-GPON-1110-WDONT routerBrowse SyroTech / SyroTech SY-GPON-1110-WDONT routerDefault status: unaffected | CVE List | 3.1.02-231102 | affected |
sy-gpon-1110-wdont_firmwareBrowse syrotech / sy-gpon-1110-wdont_firmwareDefault status: unknown | CVE List | 3.1.02-231102 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-41686 cert-in.org.inThird-party advisory
https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225