CVE-2024-0716

A vulnerability classified as problematic has been found in Byzoro Smart S150 Management Platform V31R02B15. This affects an unknown part of the file /log/download.php of the component Backup File Handler. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-251541 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:byzoro:smart_s150_firmware:31r02b15:*:*:*:*:*:*:*
cpe:2.3:h:byzoro:smart_s150:-:*:*:*:*:*:*:*

History

09 Apr 2024, 09:15

Type Values Removed Values Added
Summary (en) A vulnerability classified as problematic has been found in Beijing Baichuo Smart S150 Management Platform V31R02B15. This affects an unknown part of the file /log/download.php of the component Backup File Handler. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-251541 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. (en) A vulnerability classified as problematic has been found in Byzoro Smart S150 Management Platform V31R02B15. This affects an unknown part of the file /log/download.php of the component Backup File Handler. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-251541 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
References
  • () https://vuldb.com/?submit.265177 -

25 Jan 2024, 22:19

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad ha sido encontrada en Beijing Baichuo Smart S150 Management Platform V31R02B15 y clasificada como problemática. Una parte desconocida del archivo /log/download.php del componente Backup File Handler es afectada por una función desconocida. La manipulación conduce a la divulgación de información. Es posible iniciar el ataque de forma remota. La complejidad de un ataque es bastante alta. Se dice que la explotabilidad es difícil. El exploit ha sido divulgado al público y puede utilizarse. A esta vulnerabilidad se le asignó el identificador VDB-251541. NOTA: Se contactó primeramente con el proveedor sobre esta divulgación, pero no respondió de ninguna manera.
References () https://github.com/GTA12138/vul/blob/main/smart%20s150/s150%20Download%20any%20file/smart%20s150%20download%20any%20file.md - () https://github.com/GTA12138/vul/blob/main/smart%20s150/s150%20Download%20any%20file/smart%20s150%20download%20any%20file.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.251541 - () https://vuldb.com/?ctiid.251541 - Third Party Advisory
References () https://vuldb.com/?id.251541 - () https://vuldb.com/?id.251541 - Third Party Advisory
CPE cpe:2.3:o:byzoro:smart_s150_firmware:31r02b15:*:*:*:*:*:*:*
cpe:2.3:h:byzoro:smart_s150:-:*:*:*:*:*:*:*
First Time Byzoro
Byzoro smart S150 Firmware
Byzoro smart S150
CWE NVD-CWE-noinfo
CVSS v2 : 2.1
v3 : 3.1
v2 : 2.1
v3 : 5.3

19 Jan 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-19 15:15

Updated : 2024-04-11 01:24


NVD link : CVE-2024-0716

Mitre link : CVE-2024-0716

CVE.ORG link : CVE-2024-0716


JSON object : View

Products Affected

byzoro

  • smart_s150_firmware
  • smart_s150
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor