CVE-2023-22597
Summary
| CVE | CVE-2023-22597 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-12 23:15:00 UTC |
| Updated | 2023-11-07 04:07:00 UTC |
| Description | InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-319: Cleartext Transmission of Sensitive Information. They use an unsecured channel to communicate with the cloud platform by default. An unauthorized user could intercept this communication and steal sensitive information such as configuration information and MQTT credentials; this could allow MQTT command injection. |
Risk And Classification
Problem Types: CWE-319
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Inhandnetworks | Inrouter302 | - | All | All | All |
| Operating System | Inhandnetworks | Inrouter302 Firmware | All | All | All | All |
| Hardware | Inhandnetworks | Inrouter615-s | - | All | All | All |
| Operating System | Inhandnetworks | Inrouter615-s Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| InHand Networks InRouter | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.