CVE-2023-26588

Use of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to access the debug function of the product. The affected products and versions are as follows: BS-GSL2024 firmware Ver. 1.10-0.03 and earlier, BS-GSL2016P firmware Ver. 1.10-0.03 and earlier, BS-GSL2016 firmware Ver. 1.10-0.03 and earlier, BS-GS2008 firmware Ver. 1.0.10.01 and earlier, BS-GS2016 firmware Ver. 1.0.10.01 and earlier, BS-GS2024 firmware Ver. 1.0.10.01 and earlier, BS-GS2048 firmware Ver. 1.0.10.01 and earlier, BS-GS2008P firmware Ver. 1.0.10.01 and earlier, BS-GS2016P firmware Ver. 1.0.10.01 and earlier, and BS-GS2024P firmware Ver. 1.0.10.01 and earlier
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:buffalo:bs-gsl2024_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gsl2024:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:buffalo:bs-gsl2016p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gsl2016p:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:buffalo:bs-gsl2016_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gsl2016:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2008_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2008:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2016_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2016:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2024_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2024:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2048_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2048:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2008p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2008p:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2016p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2016p:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2024p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2024p:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:buffalo:bs-gsl2005_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gsl2005:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:buffalo:bs-gsl2008_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gsl2008:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:buffalo:bs-gsl2005p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gsl2005p:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:buffalo:bs-gsl2008p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gsl2008p:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2016p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2016p:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2016hp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2016hp:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2024p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2024p:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2024hp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2024hp:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:51

Type Values Removed Values Added
References () https://jvn.jp/en/vu/JVNVU96824262/ - Patch, Third Party Advisory () https://jvn.jp/en/vu/JVNVU96824262/ - Patch, Third Party Advisory
References () https://www.buffalo.jp/news/detail/20230310-01.html - Vendor Advisory () https://www.buffalo.jp/news/detail/20230310-01.html - Vendor Advisory

Information

Published : 2023-04-11 09:15

Updated : 2024-11-21 07:51


NVD link : CVE-2023-26588

Mitre link : CVE-2023-26588

CVE.ORG link : CVE-2023-26588


JSON object : View

Products Affected

buffalo

  • bs-gsl2008_firmware
  • bs-gsl2008p_firmware
  • bs-gs2008
  • bs-gs2048_firmware
  • bs-gsl2016
  • bs-gs2024hp_firmware
  • bs-gs2016hp_firmware
  • bs-gsl2005p_firmware
  • bs-gs2024p
  • bs-gsl2016p_firmware
  • bs-gs2008p
  • bs-gsl2024_firmware
  • bs-gsl2005p
  • bs-gs2016_firmware
  • bs-gs2048
  • bs-gsl2008p
  • bs-gs2008p_firmware
  • bs-gs2016p
  • bs-gs2024
  • bs-gsl2016p
  • bs-gsl2016_firmware
  • bs-gs2016
  • bs-gs2016p_firmware
  • bs-gs2008_firmware
  • bs-gsl2005
  • bs-gsl2024
  • bs-gs2016hp
  • bs-gsl2005_firmware
  • bs-gs2024_firmware
  • bs-gs2024hp
  • bs-gsl2008
  • bs-gs2024p_firmware
CWE
CWE-668

Exposure of Resource to Wrong Sphere