CVE Vulnerabilities

CVE-2023-31195

Cleartext Transmission of Sensitive Information

Published: Jun 13, 2023 | Modified: Jan 03, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without Secure attribute. When an attacker is in a position to be able to mount a man-in-the-middle attack, and a user is tricked to log into the affected device through an unencrypted (http) connection, the users session may be hijacked.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Rt-ax3000_firmware Asus * 3.0.0.4.388.23403 (excluding)

Potential Mitigations

References