CVE-2023-24544

Improper access control vulnerability in Buffalo network devices allows a network-adjacent attacker to obtain specific files of the product. As a result, the product settings may be altered. The affected products and versions are as follows: BS-GSL2024 firmware Ver. 1.10-0.03 and earlier, BS-GSL2016P firmware Ver. 1.10-0.03 and earlier, BS-GSL2016 firmware Ver. 1.10-0.03 and earlier, BS-GS2008 firmware Ver. 1.0.10.01 and earlier, BS-GS2016 firmware Ver. 1.0.10.01 and earlier, BS-GS2024 firmware Ver. 1.0.10.01 and earlier, BS-GS2048 firmware Ver. 1.0.10.01 and earlier, BS-GS2008P firmware Ver. 1.0.10.01 and earlier, BS-GS2016P firmware Ver. 1.0.10.01 and earlier, and BS-GS2024P firmware Ver. 1.0.10.01 and earlier
References
Link Resource
https://jvn.jp/en/vu/JVNVU96824262/ Third Party Advisory
https://www.buffalo.jp/news/detail/20230310-01.html Patch Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:buffalo:bs-gsl2024_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gsl2024:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:buffalo:bs-gsl2016p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gsl2016p:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:buffalo:bs-gsl2016_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gsl2016:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2008_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2008:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2016_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2016:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2024_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2024:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2048_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2048:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2008p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2008p:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2016p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2016p:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2024p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2024p:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2016p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2016p:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2016hp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2016hp:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2024p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2024p:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2024hp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2024hp:-:*:*:*:*:*:*:*

History

18 Apr 2023, 19:36

Type Values Removed Values Added
CPE cpe:2.3:o:buffalo:bs-gs2016hp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gsl2016p:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bs-gs2008p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bs-gsl2024_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bs-gs2024p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2024p:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bs-gsl2016p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bs-gs2016_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2016hp:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gsl2024:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bs-gsl2016_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bs-gs2016p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bs-gs2048_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2016p:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bs-gs2008_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2008p:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2048:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2024:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gsl2016:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2008:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bs-gs2024_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2016:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2024hp:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bs-gs2024hp_firmware:*:*:*:*:*:*:*:*
First Time Buffalo bs-gs2024 Firmware
Buffalo bs-gs2016
Buffalo bs-gs2008p
Buffalo bs-gsl2024
Buffalo
Buffalo bs-gs2024p Firmware
Buffalo bs-gsl2016p Firmware
Buffalo bs-gs2016p
Buffalo bs-gsl2024 Firmware
Buffalo bs-gs2016hp Firmware
Buffalo bs-gs2048
Buffalo bs-gsl2016 Firmware
Buffalo bs-gs2024hp Firmware
Buffalo bs-gs2008p Firmware
Buffalo bs-gs2008 Firmware
Buffalo bs-gs2048 Firmware
Buffalo bs-gs2024hp
Buffalo bs-gs2008
Buffalo bs-gsl2016
Buffalo bs-gs2024p
Buffalo bs-gs2016p Firmware
Buffalo bs-gs2016hp
Buffalo bs-gs2024
Buffalo bs-gs2016 Firmware
Buffalo bs-gsl2016p
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CWE NVD-CWE-noinfo
References (MISC) https://jvn.jp/en/vu/JVNVU96824262/ - (MISC) https://jvn.jp/en/vu/JVNVU96824262/ - Third Party Advisory
References (MISC) https://www.buffalo.jp/news/detail/20230310-01.html - (MISC) https://www.buffalo.jp/news/detail/20230310-01.html - Patch, Vendor Advisory

11 Apr 2023, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-11 09:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-24544

Mitre link : CVE-2023-24544

CVE.ORG link : CVE-2023-24544


JSON object : View

Products Affected

buffalo

  • bs-gs2016hp_firmware
  • bs-gs2008
  • bs-gs2024
  • bs-gs2048
  • bs-gs2024hp_firmware
  • bs-gs2024p
  • bs-gs2016_firmware
  • bs-gs2008p_firmware
  • bs-gsl2016_firmware
  • bs-gs2016p_firmware
  • bs-gs2024_firmware
  • bs-gs2016p
  • bs-gs2008p
  • bs-gs2024p_firmware
  • bs-gsl2024
  • bs-gs2016hp
  • bs-gsl2024_firmware
  • bs-gsl2016p
  • bs-gs2008_firmware
  • bs-gs2016
  • bs-gsl2016
  • bs-gs2048_firmware
  • bs-gs2024hp
  • bs-gsl2016p_firmware