HIGH · 8.6

CVE-2023-22441

Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attacker to obtain or alter the setting information of the product or execute some cri...

Vulnerability Description

Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attacker to obtain or alter the setting information of the product or execute some critical functions without authentication, e.g., rebooting the product. Affected products and versions are as follows: SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, and SkyBridge BASIC MB-A130 firmware Ver. 1.4.1 and earlier

CVSS Score

8.6

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
HIGH

Affected Products

VendorProductVersions
Seiko-SolSkybridge Basic Mb-A130 Firmware<= 1.4.1
Seiko-SolSkybridge Basic Mb-A130-
Seiko-SolSkybridge Mb-A200 Firmware<= 01.00.05
Seiko-SolSkybridge Mb-A200-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-22441?

CVE-2023-22441 is a vulnerability with a CVSS score of 8.6 (HIGH). Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attacker to obtain or alter the setting information of the product or execute some cri...

How severe is CVE-2023-22441?

CVE-2023-22441 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-22441?

Check the references section above for vendor advisories and patch information. Affected products include: Seiko-Sol Skybridge Basic Mb-A130 Firmware, Seiko-Sol Skybridge Basic Mb-A130, Seiko-Sol Skybridge Mb-A200 Firmware, Seiko-Sol Skybridge Mb-A200.