CVE-2023-3330

EUVD-2023-43998
Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all versions allows a attacker to obtain specific files in the product.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
Affected Products (NVD)
VendorProductVersion
necaterm_wf300hp_firmware
-
necaterm_wg1400hp_firmware
-
necaterm_wg1800hp_firmware
-
necaterm_wg1800hp2_firmware
-
necaterm_wg2200hp_firmware
-
necaterm_wg2600hp_firmware
-
necaterm_wg2600hp2_firmware
-
necaterm_wg300hp_firmware
-
necaterm_wg600hp_firmware
-
necaterm_wr8600n_firmware
-
necaterm_wr8700n_firmware
-
necaterm_wr8750n_firmware
-
necaterm_wr9300n_firmware
-
necaterm_wr9500n_firmware
-
necaterm_wr8170n_firmware
-
necaterm_wr8175n_firmware
-
necaterm_wr8370n_firmware
-
𝑥
= Vulnerable software versions