« Volver al listado

CVE-2024-23486

Estado: AnalizadaCrítica (9.8)—

Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker with access to the product's login page may obtain configured credentials.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-23486",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-23486",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-04-17T20:26:00.951617Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "BUFFALO INC.",
          "product": "WSR-2533DHP",
          "versions": [
            {
              "status": "affected",
              "version": "firmware Ver. 1.06 and earlier"
            }
          ]
        },
        {
          "vendor": "BUFFALO INC.",
          "product": "WSR-2533DHPL",
          "versions": [
            {
              "status": "affected",
              "version": "firmware Ver. 1.06 and earlier"
            }
          ]
        },
        {
          "vendor": "BUFFALO INC.",
          "product": "WSR-2533DHP2",
          "versions": [
            {
              "status": "affected",
              "version": "firmware Ver. 1.10 and earlier"
            }
          ]
        },
        {
          "vendor": "BUFFALO INC.",
          "product": "WSR-A2533DHP2",
          "versions": [
            {
              "status": "affected",
              "version": "firmware Ver. 1.10 and earlier"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:buffalo_inc:wsr-2533dhp2:1.06:*:*:*:*:*:*:*"
          ],
          "vendor": "buffalo_inc",
          "product": "wsr-2533dhp2",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.06",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:buffalo_inc:a2533dhp2:1.06:*:*:*:*:*:*:*"
          ],
          "vendor": "buffalo_inc",
          "product": "a2533dhp2",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.06",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:buffalo:a2533dhp2:1.06:*:*:*:*:*:*:*"
          ],
          "vendor": "buffalo",
          "product": "a2533dhp2",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1,06",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:buffalo:wsr-2533dhpl:1.06:*:*:*:*:*:*:*"
          ],
          "vendor": "buffalo",
          "product": "wsr-2533dhpl",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.06",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-04-15T11:15:07.820",
  "references": [
    {
      "url": "https://jvn.jp/en/jp/JVN58236836/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.buffalo.jp/news/detail/20240410-01.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN58236836/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.buffalo.jp/news/detail/20240410-01.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-256"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker with access to the product's login page may obtain configured credentials."
    },
    {
      "lang": "es",
      "value": "Existe un problema de almacenamiento de texto plano de contraseña en los routers LAN inalámbricos BUFFALO, lo que puede permitir que un atacante no autenticado adyacente a la red con acceso a la página de inicio de sesión del producto pueda obtener las credenciales configuradas."
    }
  ],
  "lastModified": "2026-06-17T07:13:02.687",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:buffalo:wsr-2533dhp_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6B9870CC-E71F-4E52-A4F0-8788D5B42B5B",
              "versionEndExcluding": "1.07"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:buffalo:wsr-2533dhp:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1574DB7C-A19C-45B5-AD37-4C0AFE8CC798"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:buffalo:wsr-2533dhpl_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06725D59-C185-4FD0-B4D0-06FDD4923F07",
              "versionEndExcluding": "1.07"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:buffalo:wsr-2533dhpl:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C23EE312-9ADE-4B0B-B7ED-F61AC441E5DB"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:buffalo:wsr-2533dhp2_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B6ED9EEE-8ACA-41C8-A702-4C3DD82779E0",
              "versionEndExcluding": "1.11"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:buffalo:wsr-2533dhp2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "08F476D3-8329-44B1-A2B0-B2AEB500863F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:buffalo:wsr-a2533dhp2_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E179106-AA75-4EF0-B106-CD7E78302837",
              "versionEndExcluding": "1.11"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:buffalo:wsr-a2533dhp2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9BF474D3-21B8-47D5-BC18-443295C51638"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}