← volver
CVE-2023-31279

Improper Authentication

CVSS 8.1 HIGHEPSS 0.4%CWE-287
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.1EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
20 dic 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The AirVantage platform is vulnerable to an unauthorized attacker registering previously unregistered devices on the AirVantage platform when the owner has not disabled the AirVantage Management Service on the devices or registered the device. This could enable an attacker to configure, manage, and execute AT commands on an unsuspecting user’s devices.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H