CVE-2023-39171
Published Dec 7, 2023SENEC Storage Box V1,V2 and V3 accidentially expose a management UI accessible with publicly known admin credentials.
Vendor/product archive
4 CVEs tagged to enbw / senec_storage_box_firmware — 2 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.
SENEC Storage Box V1,V2 and V3 accidentially expose a management UI accessible with publicly known admin credentials.
The affected devices use publicly available default credentials with administrative privileges.
The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture and modify network traffic.
In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensitive data.