CRITICAL🇵🇱 Wersja polska

CVE-2023-22601

CVSS 10.0v3.1pub. 2023-01-12upd. 2024-11-21

InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-330: Use of Insufficiently Random Values. They do not properly randomize MQTT ClientID parameters. An unauthorized user could calculate this parameter and use it to gather additional information about other InHand devices managed on the same cloud platform.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
  • Inhandnetworks Inrouter302

    HW
    Inhandnetworks
    all versions
  • Inhandnetworks Inrouter302 Firmware

    OS
    Inhandnetworks
    < 3.5.56
  • Inhandnetworks Inrouter615 S

    HW
    Inhandnetworks
    all versions
  • Inhandnetworks Inrouter615 S Firmware

    OS
    Inhandnetworks
    < 2.3.0.r5542
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-22600CRITICAL10.0PL ✓same product

Nieautoryzowany dostęp do MQTT w routerach InHand Networks InRouter 302/615

CVE-2022-25932CRITICAL9.8PL ✓same product

Niekompletne poprawki privilege escalation w InHand Networks InRouter302

CVE-2023-22599HIGH7.0same product

InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-...

CVE-2023-22598HIGH7.2same product

InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-...

CVE-2022-21182HIGH8.8same product

A privilege escalation vulnerability exists in the router configuration import functionality of InHand Network...