VulnerabilityModified
CVE-2023-36611
The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege.
MEDIUM 6.5EPSS 0.51%
Does this matter?
Lower severity and a low EPSS score (0.51%). Track it; it rarely justifies an emergency change on its own.
Description
The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could allow an attacker with “user” privileges to access files requiring higher privileges by establishing an SSH session and providing the other tokens.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.51% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285
- Affected
- ovarro/tbox ms-cpu32 firmware · ovarro/tbox ms-cpu32-s2 firmware · ovarro/tbox lt2 firmware · ovarro/tbox tg2 firmware · ovarro/tbox rm2 firmware
- Source
- ics-cert@hq.dhs.gov
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-180-03Mitigation, Third Party Advisory, US Government Resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-180-03Mitigation, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.