CVE-2023-41354 describes a vulnerability in Chunghwa Telecom NOKIA G-040W-Q firewalls where the default configuration fails to block ICMP TIMESTAMP requests. This allows an unauthenticated remote attacker to exploit the flaw by sending a crafted package, leading to the exposure of partially sensitive information. Rated as MEDIUM severity with a CVSS score of 5.3, the attack requires no user interaction or privileges and has low complexity, primarily impacting confidentiality. There is currently no evidence of active exploitation, and public exploit code (Metasploit, Nuclei, ExploitDB) is unavailable, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
g040wqr201207CPE matchmatch criteria | cpe:2.3:o:nokia:g-040w-q_firmware:g040wqr201207:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.