ID

VAR-202301-2250


CVE

CVE-2023-24508


TITLE

Multiple Baicells Nova Product cross-site scripting vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-202301-1947

DESCRIPTION

Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB and Nova 246 devices with firmware through RTS/RTD 3.6.6 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods below have been tested and validated by a 3rd party analyst and has been confirmed exploitable special thanks to Rustam Amin for providing the steps to reproduce

Trust: 0.99

sources: NVD: CVE-2023-24508 // VULMON: CVE-2023-24508

IOT TAXONOMY

category:['network device']sub_category:base station

Trust: 0.1

sources: OTHER: None

AFFECTED PRODUCTS

vendor:baicellsmodel:rtdscope:ltversion:3.7.11.6

Trust: 1.0

vendor:baicellsmodel:rtsscope:ltversion:3.7.11.6

Trust: 1.0

sources: NVD: CVE-2023-24508

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2023-24508
value: CRITICAL

Trust: 1.0

security@baicells.com: CVE-2023-24508
value: HIGH

Trust: 1.0

CNNVD: CNNVD-202301-1947
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2023-24508
baseSeverity: CRITICAL
baseScore: 9.6
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 6.0
version: 3.1

Trust: 1.0

security@baicells.com: CVE-2023-24508
baseSeverity: HIGH
baseScore: 8.1
vectorString: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: HIGH
availabilityImpact: LOW
exploitabilityScore: 2.2
impactScore: 5.3
version: 3.1

Trust: 1.0

sources: CNNVD: CNNVD-202301-1947 // NVD: CVE-2023-24508 // NVD: CVE-2023-24508

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.0

sources: NVD: CVE-2023-24508

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202301-1947

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-202301-1947

PATCH

title:Multiple Baicells Nova Fixes for product cross-site scripting vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=224335

Trust: 0.6

sources: CNNVD: CNNVD-202301-1947

EXTERNAL IDS

db:NVDid:CVE-2023-24508

Trust: 1.8

db:AUSCERTid:ESB-2023.0624

Trust: 0.6

db:CNNVDid:CNNVD-202301-1947

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

db:VULMONid:CVE-2023-24508

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2023-24508 // CNNVD: CNNVD-202301-1947 // NVD: CVE-2023-24508

REFERENCES

url:https://img.baicells.com//upload/20230118/file/baibs_rts_3.7.11.6.img.img

Trust: 1.7

url:https://img.baicells.com//upload/20230118/file/baibs_rts_3.7.11.6_changelog.pdf.pdf

Trust: 1.7

url:https://www.auscert.org.au/bulletins/esb-2023.0624

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2023-24508/

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2023-24508

Trust: 0.6

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2023-24508 // CNNVD: CNNVD-202301-1947 // NVD: CVE-2023-24508

SOURCES

db:OTHERid: -
db:VULMONid:CVE-2023-24508
db:CNNVDid:CNNVD-202301-1947
db:NVDid:CVE-2023-24508

LAST UPDATE DATE

2025-01-30T22:31:06.498000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2023-24508date:2023-01-27T00:00:00
db:CNNVDid:CNNVD-202301-1947date:2023-02-09T00:00:00
db:NVDid:CVE-2023-24508date:2023-11-07T04:08:30.450

SOURCES RELEASE DATE

db:VULMONid:CVE-2023-24508date:2023-01-26T00:00:00
db:CNNVDid:CNNVD-202301-1947date:2023-01-26T00:00:00
db:NVDid:CVE-2023-24508date:2023-01-26T21:18:19.737