CVE-2023-24464

Stored-cross-site scripting vulnerability in Buffalo network devices allows an attacker with access to the web management console of the product to execute arbitrary JavaScript on a legitimate user's web browser. The affected products and versions are as follows: BS-GS2008 firmware Ver. 1.0.10.01 and earlier, BS-GS2016 firmware Ver. 1.0.10.01 and earlier, BS-GS2024 firmware Ver. 1.0.10.01 and earlier, BS-GS2048 firmware Ver. 1.0.10.01 and earlier, BS-GS2008P firmware Ver. 1.0.10.01 and earlier, BS-GS2016P firmware Ver. 1.0.10.01 and earlier, and BS-GS2024P firmware Ver. 1.0.10.01 and earlier
References
Link Resource
https://jvn.jp/en/vu/JVNVU96824262/ Third Party Advisory VDB Entry
https://www.buffalo.jp/news/detail/20230310-01.html Patch Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2008_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2008:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2016_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2016:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2024_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2024:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2048_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2048:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2008p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2008p:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2016p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2016p:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2024p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2024p:-:*:*:*:*:*:*:*

History

18 Apr 2023, 02:21

Type Values Removed Values Added
References (MISC) https://jvn.jp/en/vu/JVNVU96824262/ - (MISC) https://jvn.jp/en/vu/JVNVU96824262/ - Third Party Advisory, VDB Entry
References (MISC) https://www.buffalo.jp/news/detail/20230310-01.html - (MISC) https://www.buffalo.jp/news/detail/20230310-01.html - Patch, Vendor Advisory
CPE cpe:2.3:h:buffalo:bs-gs2016p:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2008p:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2048:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bs-gs2008p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2024p:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bs-gs2024p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2024:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bs-gs2016_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2008:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bs-gs2024_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2016:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bs-gs2016p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bs-gs2048_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bs-gs2008_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
First Time Buffalo bs-gs2008p Firmware
Buffalo bs-gs2024 Firmware
Buffalo bs-gs2008 Firmware
Buffalo bs-gs2048 Firmware
Buffalo bs-gs2016
Buffalo bs-gs2008
Buffalo bs-gs2008p
Buffalo bs-gs2016p
Buffalo bs-gs2024p
Buffalo
Buffalo bs-gs2024p Firmware
Buffalo bs-gs2016p Firmware
Buffalo bs-gs2024
Buffalo bs-gs2016 Firmware
Buffalo bs-gs2048
CWE CWE-79

11 Apr 2023, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-11 09:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-24464

Mitre link : CVE-2023-24464

CVE.ORG link : CVE-2023-24464


JSON object : View

Products Affected

buffalo

  • bs-gs2008
  • bs-gs2024
  • bs-gs2048
  • bs-gs2008_firmware
  • bs-gs2016p_firmware
  • bs-gs2024_firmware
  • bs-gs2016
  • bs-gs2016p
  • bs-gs2008p
  • bs-gs2024p_firmware
  • bs-gs2024p
  • bs-gs2016_firmware
  • bs-gs2048_firmware
  • bs-gs2008p_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')