CVE-2023-5959 MEDIUM

CVE-2023-5959: Byzoro Smart S85F Management Platform login.php password recovery

Vendor Byzoro
Product Smart S85F Management Platform
Weakness CWE-640 · Weak password recovery
Published November 11, 2023
Last update August 2, 2024

CVSS base score

4.3/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

A vulnerability, which was classified as problematic, was found in Byzoro Smart S85F Management Platform V31R02B10-01. Affected is an unknown function of the file /login.php. The manipulation of the argument txt_newpwd leads to weak password recovery. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-244992. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Key dates

02Disclosure timeline

November 11, 2023 CVE published
August 2, 2024 Record updated

Related vulnerabilities

04Related CVE