CVE-2024-4231
MEDIUM 6.8EPSS 0.6%
This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by identifying UART pins and accessing the root shell on the vulnerable system.Successful exploitation of this vulnerability could allow the attacker to access the sensitive information on the targeted system.
- CVSS v4.0
- 6.8 MEDIUM
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - CVSS v3.1
- 4.6 MEDIUM
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS
- 0.56% chance of exploitation in the next 30 days, 45th percentile
- Published
- 2024-05-10
- Updated
- 2024-08-01
Proof-of-concept exploits (2)
- Redfox-Secuirty/Digisol-DG-GR1321-s-Improper-Access-Control-CVE-2024-42310★ · 2024-06-18
- Redfox-Security/Digisol-DG-GR1321-s-Improper-Access-Control-CVE-2024-42310★ · 2024-06-18