CVE-2024-0716

A vulnerability classified as problematic has been found in Byzoro Smart S150 Management Platform V31R02B15. This affects an unknown part of the file /log/download.php of the component Backup File Handler. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-251541 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:byzoro:smart_s150_firmware:31r02b15:*:*:*:*:*:*:*
cpe:2.3:h:byzoro:smart_s150:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:47

Type Values Removed Values Added
References () https://github.com/GTA12138/vul/blob/main/smart%20s150/s150%20Download%20any%20file/smart%20s150%20download%20any%20file.md - Exploit, Third Party Advisory () https://github.com/GTA12138/vul/blob/main/smart%20s150/s150%20Download%20any%20file/smart%20s150%20download%20any%20file.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.251541 - Third Party Advisory () https://vuldb.com/?ctiid.251541 - Third Party Advisory
References () https://vuldb.com/?id.251541 - Third Party Advisory () https://vuldb.com/?id.251541 - Third Party Advisory
References () https://vuldb.com/?submit.265177 - () https://vuldb.com/?submit.265177 -
CVSS v2 : 2.1
v3 : 5.3
v2 : 2.1
v3 : 3.1

21 Oct 2024, 12:35

Type Values Removed Values Added
CWE CWE-532

09 Apr 2024, 09:15

Type Values Removed Values Added
Summary (en) A vulnerability classified as problematic has been found in Beijing Baichuo Smart S150 Management Platform V31R02B15. This affects an unknown part of the file /log/download.php of the component Backup File Handler. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-251541 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. (en) A vulnerability classified as problematic has been found in Byzoro Smart S150 Management Platform V31R02B15. This affects an unknown part of the file /log/download.php of the component Backup File Handler. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-251541 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
References
  • () https://vuldb.com/?submit.265177 -

25 Jan 2024, 22:19

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:h:byzoro:smart_s150:-:*:*:*:*:*:*:*
cpe:2.3:o:byzoro:smart_s150_firmware:31r02b15:*:*:*:*:*:*:*
First Time Byzoro smart S150 Firmware
Byzoro
Byzoro smart S150
CWE CWE-200 NVD-CWE-noinfo
References () https://github.com/GTA12138/vul/blob/main/smart%20s150/s150%20Download%20any%20file/smart%20s150%20download%20any%20file.md - () https://github.com/GTA12138/vul/blob/main/smart%20s150/s150%20Download%20any%20file/smart%20s150%20download%20any%20file.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.251541 - () https://vuldb.com/?ctiid.251541 - Third Party Advisory
References () https://vuldb.com/?id.251541 - () https://vuldb.com/?id.251541 - Third Party Advisory

19 Jan 2024, 15:56

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-19 15:15

Updated : 2024-11-21 08:47


NVD link : CVE-2024-0716

Mitre link : CVE-2024-0716

CVE.ORG link : CVE-2024-0716


JSON object : View

Products Affected

byzoro

  • smart_s150_firmware
  • smart_s150
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo CWE-532

Insertion of Sensitive Information into Log File