CVE-2023-24464

S

tored-cross-site scripting vulnerability in Buffalo network devices allows an attacker with access to the web management console of the product to execute arbitrary JavaScript on a legitimate user's web browser. The affected products and versions are as follows: BS-GS2008 firmware Ver. 1.0.10.01 and earlier, BS-GS2016 firmware Ver. 1.0.10.01 and earlier, BS-GS2024 firmware Ver. 1.0.10.01 and earlier, BS-GS2048 firmware Ver. 1.0.10.01 and earlier, BS-GS2008P firmware Ver. 1.0.10.01 and earlier, BS-GS2016P firmware Ver. 1.0.10.01 and earlier, and BS-GS2024P firmware Ver. 1.0.10.01 and earlier

References
Link Resource
https://jvn.jp/en/vu/JVNVU96824262/ Third Party Advisory VDB Entry
https://www.buffalo.jp/news/detail/20230310-01.html Patch Vendor Advisory
https://jvn.jp/en/vu/JVNVU96824262/ Third Party Advisory VDB Entry
https://www.buffalo.jp/news/detail/20230310-01.html Patch Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2008_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2008:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2016_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2016:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2024_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2024:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2048_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2048:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2008p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2008p:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2016p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2016p:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:buffalo:bs-gs2024p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bs-gs2024p:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:47

Type Values Removed Values Added
References () https://jvn.jp/en/vu/JVNVU96824262/ - Third Party Advisory, VDB Entry () https://jvn.jp/en/vu/JVNVU96824262/ - Third Party Advisory, VDB Entry
References () https://www.buffalo.jp/news/detail/20230310-01.html - Patch, Vendor Advisory () https://www.buffalo.jp/news/detail/20230310-01.html - Patch, Vendor Advisory

Information

Published : 2023-04-11 09:15

Updated : 2025-02-11 17:15


NVD link : CVE-2023-24464

Mitre link : CVE-2023-24464

CVE.ORG link : CVE-2023-24464


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')