MEDIUM · 6.5

CVE-2022-34840

Use of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to alter?configuration settings of the device. The affected products/versions are as ...

Vulnerability Description

Use of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to alter?configuration settings of the device. The affected products/versions are as follows: WZR-300HP firmware Ver. 2.00 and earlier, WZR-450HP firmware Ver. 2.00 and earlier, WZR-600DHP firmware Ver. 2.00 and earlier, WZR-900DHP firmware Ver. 1.15 and earlier, HW-450HP-ZWE firmware Ver. 2.00 and earlier, WZR-450HP-CWT firmware Ver. 2.00 and earlier, WZR-450HP-UB firmware Ver. 2.00 and earlier, WZR-600DHP2 firmware Ver. 1.15 and earlier, and WZR-D1100H firmware Ver. 2.00 and earlier.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
BuffaloWzr-300Hp Firmware<= 2.00
BuffaloWzr-300Hp-
BuffaloWzr-450Hp Firmware<= 2.00
BuffaloWzr-450Hp-
BuffaloWzr-600Dhp Firmware<= 2.00
BuffaloWzr-600Dhp-
BuffaloWzr-900Dhp Firmware<= 1.15
BuffaloWzr-900Dhp-
BuffaloHw-450Hp-Zwe Firmware<= 2.00
BuffaloHw-450Hp-Zwe-
BuffaloWzr-450Hp-Cwt Firmware<= 2.00
BuffaloWzr-450Hp-Cwt-
BuffaloWzr-450Hp-Ub Firmware<= 2.00
BuffaloWzr-450Hp-Ub-
BuffaloWzr-600Dhp2 Firmware<= 1.15
BuffaloWzr-600Dhp2-
BuffaloWzr-D1100H Firmware<= 2.00
BuffaloWzr-D1100H-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-34840?

CVE-2022-34840 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Use of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to alter?configuration settings of the device. The affected products/versions are as ...

How severe is CVE-2022-34840?

CVE-2022-34840 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-34840?

Check the references section above for vendor advisories and patch information. Affected products include: Buffalo Wzr-300Hp Firmware, Buffalo Wzr-300Hp, Buffalo Wzr-450Hp Firmware, Buffalo Wzr-450Hp, Buffalo Wzr-600Dhp Firmware.