Seiko-Sol Skybridge Basic Mb-A130 Firmware vulnerabilities
3 known vulnerabilities affecting seiko-sol/skybridge_basic_mb-a130_firmware.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2023-22441P3HIGHCVSS 8.6≤ 1.4.12023-05-10
CVE-2023-22441 [HIGH] CWE-306 CVE-2023-22441: Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may a
Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attacker to obtain or alter the setting information of the product or execute some critical functions without authentication, e.g., rebooting the product. Affected products and versions are as follows: SkyBridge MB-A200 firmware Ver. 01.00
nvd
CVE-2023-25184P3HIGHCVSS 7.5≤ 1.4.12023-05-10
CVE-2023-25184 [HIGH] CWE-521 CVE-2023-25184: Use of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a
Use of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product. Affected products and versions are as follows: SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, SkyBridge BASIC MB-A130 firmware Ver. 1.4.1 and earlier, and SkySpider
nvd
CVE-2023-23901P3MEDIUMCVSS 6.5≤ 1.4.12023-05-10
CVE-2023-23901 [MEDIUM] CWE-295 CVE-2023-23901: Improper following of a certificate's chain of trust exists in SkyBridge MB-A200 firmware Ver. 01.00
Improper following of a certificate's chain of trust exists in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, and SkyBridge BASIC MB-A130 firmware Ver. 1.4.1 and earlier, which may allow a remote unauthenticated attacker to eavesdrop on or alter the communication sent to the WebUI of the product.
nvd