← Back

CVE-2023-36607

nvd nist
Published: Jun 29, 2023Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

The affected TBox RTUs are missing authorization for running some API commands. An attacker running these commands could reveal sensitive information such as software versions and web server file contents.

Affected (5)

5 products
Tbox Ms Cpu32 Firmware
Tbox Ms Cpu32 S2 Firmware
Tbox Lt2 Firmware
Tbox Tg2 Firmware
Tbox Rm2 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.50.598
Running on/withPlatform Versions
Ovarro
Tbox Ms Cpu32
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.50.598
Running on/withPlatform Versions
Ovarro
Tbox Ms Cpu32 S2
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.50.598
Running on/withPlatform Versions
Ovarro
Tbox Lt2
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.50.598
Running on/withPlatform Versions
Ovarro
Tbox Tg2
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.50.598
Running on/withPlatform Versions
Ovarro
Tbox Rm2
All versions

References (2)

Source: ics-cert@hq.dhs.gov
MitigationThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryUS Government Resource

Timeline

No history available yet.