{"api_version":"1","generated_at":"2026-07-23T09:44:22+00:00","cve":"CVE-2023-3453","urls":{"html":"https://cve.report/CVE-2023-3453","api":"https://cve.report/api/cve/CVE-2023-3453.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-3453","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-3453"},"summary":{"title":"CVE-2023-3453","description":"ETIC Telecom RAS versions 4.7.0 and prior the web management portal authentication disabled by default. This could allow an attacker with adjacent network access to alter the configuration of the device or cause a denial-of-service condition.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2023-08-23 22:15:00","updated_at":"2023-09-01 18:11:00"},"problem_types":["CWE-1188"],"metrics":[],"references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-23-208-01","name":"https://www.cisa.gov/news-events/ics-advisories/icsa-23-208-01","refsource":"MISC","tags":[],"title":"ETIC Telecom RAS Authentication | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-3453","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-3453","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"3453","vulnerable":"1","versionEndIncluding":"4.7.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"etictelecom","cpe5":"remote_access_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-3453","ASSIGNER":"ics-cert@hq.dhs.gov","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"\nETIC Telecom RAS versions 4.7.0 and prior the web management portal authentication disabled by default. This could allow an attacker with adjacent network access to alter the configuration of the device or cause a denial-of-service condition.\n\n"}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-1188 Insecure Default Initialization of Resource","cweId":"CWE-1188"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"ETIC Telecom","product":{"product_data":[{"product_name":"Remote Access Server (RAS)","version":{"version_data":[{"version_affected":"<=","version_name":"0","version_value":"4.7.0"}]}}]}}]}},"references":{"reference_data":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-23-208-01","refsource":"MISC","name":"https://www.cisa.gov/news-events/ics-advisories/icsa-23-208-01"}]},"generator":{"engine":"Vulnogram 0.1.0-dev"},"source":{"advisory":"ICSA-23-208-01","discovery":"EXTERNAL"},"work_around":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"\n\n<p>ETIC Telecom recommends enabling the authentication mechanism on the administration interface. This can be done on the page “&gt; Setup &gt; Security &gt; Administration right” by creating an administrator on the “List of administrators” table, enabling the parameter “Password protect the configuration interface,” then setting the parameter “Protocols to use for configuration” to “HTTPs only”.</p><p>NOTE: for firmware versions 4.9.0 or later, enabling the administration protection is mandatory after the first product start.</p>\n\n<br>"}],"value":"\nETIC Telecom recommends enabling the authentication mechanism on the administration interface. This can be done on the page “> Setup > Security > Administration right” by creating an administrator on the “List of administrators” table, enabling the parameter “Password protect the configuration interface,” then setting the parameter “Protocols to use for configuration” to “HTTPs only”.\n\nNOTE: for firmware versions 4.9.0 or later, enabling the administration protection is mandatory after the first product start.\n\n\n\n\n"}],"solution":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Update to&nbsp;<span style=\"background-color: var(--wht);\">ETIC Telecom RAS: </span><a target=\"_blank\" rel=\"nofollow\" href=\"https://www.etictelecom.com/en/softwares-download/\">version 4.9.0 or later</a>"}],"value":"Update to ETIC Telecom RAS:  version 4.9.0 or later https://www.etictelecom.com/en/softwares-download/ "}],"credits":[{"lang":"en","value":"Haviv Vaizman of OTORIO"},{"lang":"en","value":"Hay Mizrachi of OTORIO"},{"lang":"en","value":"Alik Koldobsky of OTORIO"},{"lang":"en","value":"Ofir Manzur of OTORIO"},{"lang":"en","value":"Nikolay Sokolik of OTORIO"}],"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"LOW","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L","version":"3.1"}]}},"nvd":{"publishedDate":"2023-08-23 22:15:00","lastModifiedDate":"2023-09-01 18:11:00","problem_types":["CWE-1188"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:etictelecom:remote_access_server:*:*:*:*:*:*:*:*","versionEndIncluding":"4.7.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}