CVE-2023-38585

Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H, NR16H series and DR-16F, DR-8F, DR-4F, DR-16H, DR-8H, DR-4H, DR-4M41 series are no longer supported, therefore updates for those products are not provided.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:cbc:nr4h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:nr4h:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:cbc:nr8h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:nr8h:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:cbc:nr16h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:nr16h:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:cbc:dr-16f42a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:dr-16f42a:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:cbc:dr-16f45at_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:dr-16f45at:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:cbc:dr-8f42a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:dr-8f42a:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:cbc:dr-8f45at_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:dr-8f45at:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:cbc:dr-4fx1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:dr-4fx1:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:cbc:dr-16h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:dr-16h:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:cbc:dr-8h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:dr-8h:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:cbc:dr-4h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:dr-4h:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:cbc:drh8-4m41-a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:drh8-4m41-a:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:cbc:nr8-4m71_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:nr8-4m71:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:cbc:nr8-8m72_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:nr8-8m72:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:cbc:nr-16m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:nr-16m:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:cbc:nr-16f85-8pra_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:nr-16f85-8pra:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:cbc:nr-16f82-16p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:nr-16f82-16p:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:cbc:nr-4f_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:nr-4f:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:cbc:nr-8f_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:nr-8f:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:cbc:dr-16m52_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:dr-16m52:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:cbc:dr-16m52-av_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:dr-16m52-av:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:cbc:dr-8m52-av_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:dr-8m52-av:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:cbc:dr-4m51-av_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cbc:dr-4m51-av:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:13

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-23 03:15

Updated : 2024-11-21 08:13


NVD link : CVE-2023-38585

Mitre link : CVE-2023-38585

CVE.ORG link : CVE-2023-38585


JSON object : View

Products Affected

cbc

  • dr-8f42a
  • dr-16m52-av
  • nr8h_firmware
  • nr-4f
  • nr-8f_firmware
  • dr-8m52-av
  • nr16h_firmware
  • dr-16f45at_firmware
  • nr-16m_firmware
  • dr-8m52-av_firmware
  • dr-4fx1
  • drh8-4m41-a
  • nr8h
  • nr-16f82-16p
  • dr-16m52_firmware
  • dr-8f45at_firmware
  • dr-8f42a_firmware
  • dr-16h_firmware
  • dr-16f42a
  • nr-16m
  • dr-8h_firmware
  • dr-16h
  • dr-4h_firmware
  • nr-16f85-8pra
  • nr8-8m72_firmware
  • dr-8h
  • nr8-4m71_firmware
  • dr-4h
  • nr-16f82-16p_firmware
  • nr4h_firmware
  • nr16h
  • dr-4m51-av_firmware
  • nr8-4m71
  • dr-16f42a_firmware
  • drh8-4m41-a_firmware
  • dr-16m52-av_firmware
  • dr-16f45at
  • dr-8f45at
  • nr8-8m72
  • nr-16f85-8pra_firmware
  • nr-8f
  • dr-4m51-av
  • dr-4fx1_firmware
  • dr-16m52
  • nr-4f_firmware
  • nr4h
CWE
CWE-287

Improper Authentication