CVE-2024-4232
Severity CVSS v4.0:
Pending analysis
Type:
CWE-256
Plaintext Storage of a Password
Publication date:
14/05/2024
Last modified:
03/07/2024
Description
This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to lack of encryption or hashing in storing of passwords within the router&#39;s firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext passwords on the vulnerable system.<br />
<br />
Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system.
Impact
Base Score 3.x
4.10
Severity 3.x
MEDIUM