Nov. 19, 2023, 1:13 a.m. | /u/Background-Dig-3933

cybersecurity www.reddit.com

Hi,

I was doing some penetration testing on one of my own devices and noticed said device is subjectable to vulnerability that has been reported for another model of same manufacturer.

It is fixed in newer firmware versions of both models and there is CVE ID given for the vulnerability, but it doesn't have this model listed in "Known Affected Software Configurations". Is this something that should be reported and if it is, how should I progress apart from notifying …

cve cybersecurity device devices disclosures doing firmware manufacturer own penetration penetration testing testing vulnerability

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)