CVE-2023-49229
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Dec 28, 2023
Updated: Jan 4, 2024
CWE ID 862
Summary
CVE-2023-49229 is a vulnerability affecting Peplink Balance Two versions prior to 8.4.0. This issue involves a missing authorization check in the administration web service, which enables read-only, unprivileged users to access sensitive information related to the device configuration. This vulnerability could potentially be exploited to gain unauthorized insights into the network setup, potentially leading to further security risks. It's crucial for users to update their Peplink Balance Two devices to the latest version to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Peplink