« Volver al listado

CVE-2023-39172

Estado: ModificadaCrítica (9.1)—

The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture and modify network traffic.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-39172",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "info@cert.vde.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "info@cert.vde.com",
      "affectedData": [
        {
          "vendor": "SENEC",
          "product": "Storage Box V1",
          "versions": [
            {
              "status": "affected",
              "version": "V1"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "SENEC",
          "product": "Storage Box V2",
          "versions": [
            {
              "status": "affected",
              "version": "V2"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "SENEC",
          "product": "Storage Box V3",
          "versions": [
            {
              "status": "affected",
              "version": "V3"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-12-07T14:15:07.883",
  "references": [
    {
      "url": "https://seclists.org/fulldisclosure/2023/Nov/4",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "info@cert.vde.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2023/Nov/4",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://seclists.org/fulldisclosure/2023/Nov/4",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "info@cert.vde.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-319"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-319"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture and modify network traffic."
    },
    {
      "lang": "es",
      "value": "Los dispositivos afectados transmiten información confidencial sin cifrar, lo que permite a un atacante remoto no autenticado capturar y modificar el tráfico de la red."
    }
  ],
  "lastModified": "2026-06-17T06:11:40.410",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:enbw:senec_storage_box_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AF2C3F5B-266D-455B-944D-9EDBB0268439"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:enbw:senec_storage_box:v1:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1A73E447-D78F-420B-B256-1F157A6DA364"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:enbw:senec_storage_box_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AF2C3F5B-266D-455B-944D-9EDBB0268439"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:enbw:senec_storage_box:v2:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "300B219B-45CA-44C0-AC39-D94057FA8860"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:enbw:senec_storage_box_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AF2C3F5B-266D-455B-944D-9EDBB0268439"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:enbw:senec_storage_box:v3:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "449C542C-CAE3-42A9-BF45-EE6E828A4EBE"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "info@cert.vde.com"
}