CVE-2023-31195

Severity
5.3MEDIUM
EPSS
0.0%
top 86.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13

Description

ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute. When an attacker is in a position to be able to mount a man-in-the-middle attack, and a user is tricked to log into the affected device through an unencrypted ('http') connection, the user's session may be hijacked.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages2 packages

NVDasus/rt-ax3000_firmware< 3.0.0.4.388.23403
CVEListV5asustek_computer_inc./asus_router_rt-ax3000Firmware versions prior to 3.0.0.4.388.23403

🔴Vulnerability Details

2
CVEList
CVE-2023-31195: ASUS Router RT-AX3000 Firmware versions prior to 32023-06-13
GHSA
GHSA-p4qc-734h-4fcp: ASUS Router RT-AX3000 Firmware versions prior to 32023-06-13
CVE-2023-31195 (MEDIUM CVSS 5.3) | ASUS Router RT-AX3000 Firmware vers | cvebase.io