CRITICAL🇵🇱 Wersja polska

CVE-2023-6930

CVSS 9.4v3.1pub. 2023-12-19upd. 2024-11-21

EuroTel ETL3100 versions v01c01 and v01x37 suffer from an unauthenticated configuration and log download vulnerability. This enables the attacker to disclose sensitive information and assist in authentication bypass, privilege escalation, and full system access.

🤖 AI Analysis
How it works

The vulnerability results from the lack of authentication requirements when accessing endpoints that provide configuration files and device logs. An unauthorized attacker can remotely download these files over the network without any permissions and without user interaction. Data obtained in this way (e.g., credentials, keys, passwords) enables further attacks — including authentication bypass and privilege escalation leading to full system access.

Impact

An attacker can gain full access to sensitive device configuration data and logs, and then use them to bypass authentication, escalate privileges, and take full control of the device.

Mitigation & patch

Apply patches available from the manufacturer in accordance with the references. Detailed recommendations are contained in the CISA ICS Advisory message: ICSA-23-353-05. Until the update is applied, it is recommended to restrict network access to the device only to trusted hosts and isolate the device behind a firewall.

Who is affected

EuroTel ETL3100 Firmware in versions v01c01 and v01x37

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
  • Eurotel Etl3100

    HW
    Eurotel
    all versions
  • Eurotel Etl3100 Firmware

    OS
    Eurotel
    01c0101x37
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassLPE
CWE
References

Related vulnerabilities

CVE-2023-6928CRITICAL9.8PL ✓same product

EuroTel ETL3100 — brak limitu prób logowania umożliwia przejęcie systemu

CVE-2023-6929HIGH7.5same product

EuroTel ETL3100 versions v01c01 and v01x37 are vulnerable to insecure direct object references that occur...