5.3
CVSSv3

CVE-2023-27571

Published: 15/04/2023 Updated: 21/04/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download functionality does not check the session cookie. Thus, an attacker can download all log files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

commscope dg3450_firmware ar01.02.056.18_041520_711.ncs.10

Exploits

Arris DG3450 cable gateway version AR010205618_041520_711NCS10 suffers from cross site scripting and missing authentication vulnerabilities ...