Nov. 19, 2023, 1:13 a.m. | /u/Background-Dig-3933

cybersecurity www.reddit.com

Hi,

I was doing some penetration testing on one of my own devices and noticed said device is subjectable to vulnerability that has been reported for another model of same manufacturer.

It is fixed in newer firmware versions of both models and there is CVE ID given for the vulnerability, but it doesn't have this model listed in "Known Affected Software Configurations". Is this something that should be reported and if it is, how should I progress apart from notifying …

cve cybersecurity device devices disclosures doing firmware manufacturer own penetration penetration testing testing vulnerability

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

DevSecOps Engineer

@ LinQuest | Beavercreek, Ohio, United States

Senior Developer, Vulnerability Collections (Contractor)

@ SecurityScorecard | Remote (Turkey or Latin America)

Cyber Security Intern 03416 NWSOL

@ North Wind Group | RICHLAND, WA

Senior Cybersecurity Process Engineer

@ Peraton | Fort Meade, MD, United States

Sr. Manager, Cybersecurity and Info Security

@ AESC | Smyrna, TN 37167, Smyrna, TN, US | Santa Clara, CA 95054, Santa Clara, CA, US | Florence, SC 29501, Florence, SC, US | Bowling Green, KY 42101, Bowling Green, KY, US