CVE Vulnerabilities

CVE-2024-22773

Insecure Storage of Sensitive Information

Published: Feb 06, 2024 | Modified: Apr 29, 2024
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in Login Bypass.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Action_rf_1200_firmware Intelbras 1.2.2 (including) 1.2.2 (including)

References