CVE-2023-45194
Summary
| CVE | CVE-2023-45194 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-11 01:15:00 UTC |
| Updated | 2023-10-31 18:08:00 UTC |
| Description | Use of default credentials vulnerability in MR-GM2 firmware Ver. 3.00.03 and earlier, and MR-GM3 (-D/-K/-S/-DK/-DKS/-M/-W) firmware Ver. 1.03.45 and earlier allows a network-adjacent unauthenticated attacker to intercept wireless LAN communication, when the affected product performs the communication without changing the pre-shared key from the factory-default configuration. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Mrl | Mr-gm2 | - | All | All | All |
| Operating System | Mrl | Mr-gm2 Firmware | All | All | All | All |
| Hardware | Mrl | Mr-gm3-d | - | All | All | All |
| Hardware | Mrl | Mr-gm3-dks | - | All | All | All |
| Operating System | Mrl | Mr-gm3-dks Firmware | All | All | All | All |
| Operating System | Mrl | Mr-gm3-d Firmware | All | All | All | All |
| Hardware | Mrl | Mr-gm3-k | - | All | All | All |
| Operating System | Mrl | Mr-gm3-k Firmware | All | All | All | All |
| Hardware | Mrl | Mr-gm3-m | - | All | All | All |
| Operating System | Mrl | Mr-gm3-m Firmware | All | All | All | All |
| Hardware | Mrl | Mr-gm3-s | - | All | All | All |
| Operating System | Mrl | Mr-gm3-s Firmware | All | All | All | All |
| Hardware | Mrl | Mr-gm3-w | - | All | All | All |
| Operating System | Mrl | Mr-gm3-w Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JVNVU#99039725: Multiple vulnerabilities in Micro Research MR-GM series | MISC | jvn.jp | |
| MR-GMシリーズ 脆弱性につきまして | 株式会社マイクロリサーチ | MISC | www.mrl.co.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.