CVE-2024-23618

An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to achieve code execution as root.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:commscope:arris_surfboard_sbg6950ac2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:commscope:arris_surfboard_sbg6950ac2:-:*:*:*:*:*:*:*

History

31 Jan 2024, 21:05

Type Values Removed Values Added
CVSS v2 : 8.3
v3 : 9.6
v2 : 8.3
v3 : 9.8
References () https://blog.exodusintel.com/2024/01/25/arris-surfboard-sbg6950ac2-arbitrary-command-execution-vulnerability/ - () https://blog.exodusintel.com/2024/01/25/arris-surfboard-sbg6950ac2-arbitrary-command-execution-vulnerability/ - Third Party Advisory
CPE cpe:2.3:h:commscope:arris_surfboard_sbg6950ac2:-:*:*:*:*:*:*:*
cpe:2.3:o:commscope:arris_surfboard_sbg6950ac2_firmware:-:*:*:*:*:*:*:*
First Time Commscope
Commscope arris Surfboard Sbg6950ac2 Firmware
Commscope arris Surfboard Sbg6950ac2

26 Jan 2024, 13:51

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de ejecución de código arbitrario en los dispositivos Arris SURFboard SGB6950AC2. Un atacante no autenticado puede aprovechar esta vulnerabilidad para lograr la ejecución del código como root.

26 Jan 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-26 00:15

Updated : 2024-01-31 21:05


NVD link : CVE-2024-23618

Mitre link : CVE-2024-23618

CVE.ORG link : CVE-2024-23618


JSON object : View

Products Affected

commscope

  • arris_surfboard_sbg6950ac2_firmware
  • arris_surfboard_sbg6950ac2
CWE
CWE-306

Missing Authentication for Critical Function