« Volver al listado

CVE-2023-39167

Estado: ModificadaAlta (7.5)—

In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensitive data.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-39167",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "info@cert.vde.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "info@cert.vde.com",
      "affectedData": [
        {
          "vendor": "SENEC",
          "product": "Storage Box V1",
          "versions": [
            {
              "status": "affected",
              "version": "all (until 19.06.2023)"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "SENEC",
          "product": "Storage Box V2",
          "versions": [
            {
              "status": "affected",
              "version": "all (until 19.06.2023)"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "SENEC",
          "product": "Storage Box V3",
          "versions": [
            {
              "status": "affected",
              "version": "all (until 19.06.2023)"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-12-07T14:15:07.467",
  "references": [
    {
      "url": "https://seclists.org/fulldisclosure/2023/Nov/5",
      "tags": [
        "Exploit",
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "info@cert.vde.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2023/Nov/10",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://seclists.org/fulldisclosure/2023/Nov/5",
      "tags": [
        "Exploit",
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "info@cert.vde.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensitive data."
    },
    {
      "lang": "es",
      "value": "En SENEC Storage Box V1, V2 y V3, un atacante remoto no autenticado puede obtener los archivos de registro de los dispositivos que contienen datos confidenciales."
    }
  ],
  "lastModified": "2026-06-17T06:11:40.020",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:enbw:senec_storage_box_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C6796ED-84F3-47E8-BD21-5CEBC1DD62E0",
              "versionEndIncluding": "2023-06-19"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:enbw:senec_storage_box:v1:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1A73E447-D78F-420B-B256-1F157A6DA364"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:enbw:senec_storage_box_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C6796ED-84F3-47E8-BD21-5CEBC1DD62E0",
              "versionEndIncluding": "2023-06-19"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:enbw:senec_storage_box:v2:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "300B219B-45CA-44C0-AC39-D94057FA8860"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:enbw:senec_storage_box_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C6796ED-84F3-47E8-BD21-5CEBC1DD62E0",
              "versionEndIncluding": "2023-06-19"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:enbw:senec_storage_box:v3:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "449C542C-CAE3-42A9-BF45-EE6E828A4EBE"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "info@cert.vde.com"
}