Missing Authentication for Critical Function in First Co. products - CVE-2023-47674
Published: November 27, 2023
Vulnerability identifier: #VU83492
CSH Severity: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2023-47674
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
CFR-904E
CFR-908E
CFR-916E
CFR-4EHD
CFR-8EHD
CFR-16EHD
CFR-4EHA
CFR-8EHA
CFR-16EHA
CFR-4EAAM
CFR-4EABC
CFR-4EAA
CFR-8EAA
CFR-16EAA
CFR-4EAB
CFR-8EAB
CFR-16EAB
CFR-1004EA
CFR-1008EA
CFR-1016EA
MD-404HD
MD-808HD
MD-404HA
MD-808HA
MD-404AA
MD-808AA
MD-404AB
MD-808AB
CFR-904E
CFR-908E
CFR-916E
CFR-4EHD
CFR-8EHD
CFR-16EHD
CFR-4EHA
CFR-8EHA
CFR-16EHA
CFR-4EAAM
CFR-4EABC
CFR-4EAA
CFR-8EAA
CFR-16EAA
CFR-4EAB
CFR-8EAB
CFR-16EAB
CFR-1004EA
CFR-1008EA
CFR-1016EA
MD-404HD
MD-808HD
MD-404HA
MD-808HA
MD-404AA
MD-808AA
MD-404AB
MD-808AB
Software vendor:
First Co.
First Co.
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to missing authentication for critical functionn. A remote attacker can rewrite or obtain the configuration information of the target device.
Remediation
Install updates from vendor's website for the following products.
- CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, MD-808AB