CVE-2023-1778
Estado: ModificadaCrítica (9.8)—
This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials which allows remote attacker to login as superuser by using default username/password via web-based management interface and/or exposed SSH port thereby enabling remote attackers to execute arbitrary commands with administrative/superuser privileges on the targeted systems.
The vulnerability has been addressed by forcing the user to change their default password to a new non-default password.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.13%
- Percentil entre todas las CVEs puntuadas: 65
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-287
- CWE-522
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-1778",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-1778",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-01-30T21:01:20.268732Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "vdisclose@cert-in.org.in",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 10,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "vdisclose@cert-in.org.in",
"affectedData": [
{
"vendor": "GajShield",
"product": "Data Security Firewall",
"versions": [
{
"status": "affected",
"version": "4.5",
"lessThan": "4.28",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "4.21"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-04-27T10:15:09.160",
"references": [
{
"url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2023-0119",
"tags": [
"Third Party Advisory"
],
"source": "vdisclose@cert-in.org.in"
},
{
"url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2023-0119",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "vdisclose@cert-in.org.in",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-522"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials which allows remote attacker to login as superuser by using default username/password via web-based management interface and/or exposed SSH port thereby enabling remote attackers to execute arbitrary commands with administrative/superuser privileges on the targeted systems.\n\nThe vulnerability has been addressed by forcing the user to change their default password to a new non-default password.\n"
}
],
"lastModified": "2026-06-17T05:28:44.260",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:gajshield:data_security_firewall_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CC450B0E-9218-431E-AF1E-66DAE043583E",
"versionEndExcluding": "4.21"
},
{
"criteria": "cpe:2.3:o:gajshield:data_security_firewall_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D8D28542-6331-414D-8C95-40D84D624BF1",
"versionEndExcluding": "4.28",
"versionStartIncluding": "4.22"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:gajshield:data_security_firewall:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4DC0BE30-5990-4A63-A541-2455018D94EB"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "vdisclose@cert-in.org.in"
}