CVE-2023-43848
Estado: AnalizadaAlta (8)—
Incorrect access control in the firewall management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to alter local firewall settings of the device as if they were the administrator via HTTP POST request.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.45%
- Percentil entre todas las CVEs puntuadas: 37
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-284
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-43848",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-43848",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-08-20T14:52:52.893301Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.1
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:o:aten:pe6208_firmware:2.3.228:*:*:*:*:*:*:*"
],
"vendor": "aten",
"product": "pe6208_firmware",
"versions": [
{
"status": "affected",
"version": "2.3.228"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:aten:pe6208_firmware:2.4.232:*:*:*:*:*:*:*"
],
"vendor": "aten",
"product": "pe6208_firmware",
"versions": [
{
"status": "affected",
"version": "2.4.232"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-05-28T19:15:09.587",
"references": [
{
"url": "https://github.com/setersora/pe6208",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/setersora/pe6208",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Incorrect access control in the firewall management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to alter local firewall settings of the device as if they were the administrator via HTTP POST request."
},
{
"lang": "es",
"value": "El control de acceso incorrecto en la función de administración del firewall de la interfaz web en Aten PE6208 2.3.228 y 2.4.232 permite a los usuarios autenticados remotamente modificar la configuración del firewall local del dispositivo como si fueran el administrador mediante una solicitud HTTP POST."
}
],
"lastModified": "2026-06-17T06:26:33.550",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:aten:pe6208_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CDCBDF8A-295F-4E24-B7ED-C2D8C229B2D7",
"versionEndExcluding": "2.4.239",
"versionStartIncluding": "2.3.228"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:aten:pe6208:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5D32AAB9-F426-4F0C-8705-04D0B89D52D1"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}