Vulnerability Description
Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated remote attacker can exploit this vulnerability by sending a crafted package, resulting in partially sensitive information exposed to an actor.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nokia | G-040W-Q Firmware | g040wqr201207 |
| Nokia | G-040W-Q | - |
Related Weaknesses (CWE)
References
- https://www.twcert.org.tw/tw/cp-132-7504-c6a5e-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-7504-c6a5e-1.htmlThird Party Advisory
FAQ
What is CVE-2023-41354?
CVE-2023-41354 is a vulnerability with a CVSS score of 4.0 (MEDIUM). Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated remote attacker can exploit this vulnerability by sending a crafted package, res...
How severe is CVE-2023-41354?
CVE-2023-41354 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-41354?
Check the references section above for vendor advisories and patch information. Affected products include: Nokia G-040W-Q Firmware, Nokia G-040W-Q.