Vulnerability Details CVE-2023-46711
VR-S1000 firmware Ver. 2.37 and earlier uses a hard-coded cryptographic key which may allow an attacker to analyze the password of a specific product user.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.6%
CVSS Severity
CVSS v3 Score 4.6
Products affected by CVE-2023-46711
-
cpe:2.3:h:buffalo:vr-s1000:-
-
cpe:2.3:o:buffalo:vr-s1000_firmware:1.18
-
cpe:2.3:o:buffalo:vr-s1000_firmware:1.21
-
cpe:2.3:o:buffalo:vr-s1000_firmware:2.09
-
cpe:2.3:o:buffalo:vr-s1000_firmware:2.11
-
cpe:2.3:o:buffalo:vr-s1000_firmware:2.16
-
cpe:2.3:o:buffalo:vr-s1000_firmware:2.20
-
cpe:2.3:o:buffalo:vr-s1000_firmware:2.22
-
cpe:2.3:o:buffalo:vr-s1000_firmware:2.24
-
cpe:2.3:o:buffalo:vr-s1000_firmware:2.27
-
cpe:2.3:o:buffalo:vr-s1000_firmware:2.28
-
cpe:2.3:o:buffalo:vr-s1000_firmware:2.32
-
cpe:2.3:o:buffalo:vr-s1000_firmware:2.33
-
cpe:2.3:o:buffalo:vr-s1000_firmware:2.35
-
cpe:2.3:o:buffalo:vr-s1000_firmware:2.36
-
cpe:2.3:o:buffalo:vr-s1000_firmware:2.37