5.3
CVSSv3

CVE-2023-38324

Published: 17/11/2023 Updated: 26/01/2024
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in OpenNDS prior to 10.1.2. It allows users to skip the splash page sequence (and directly authenticate) when it is using the default FAS key and OpenNDS is configured as FAS.

Vulnerable Product Search on Vulmon Subscribe to Product

opennds captive portal

Vendor Advisories

Debian Bug report logs - #1059451 opennds: CVE-2023-38313 CVE-2023-38314 CVE-2023-38315 CVE-2023-38316 CVE-2023-38320 CVE-2023-38322 CVE-2023-38324 Package: src:opennds; Maintainer for src:opennds is Debian Edu Packaging Team <debian-edu-pkg-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianor ...