CVE-2023-39457
Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.03%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. The specific flaw exists due to the lack of user authentication. The issue results from missing authentication in the default system configuration. An attacker can leverage this vulnerability to execute arbitrary code in the context of root. Was ZDI-CAN-20501.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.03% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- trianglemicroworks/scada data gateway
- Source
- zdi-disclosures@trendmicro.com
References
- https://www.trianglemicroworks.com/products/scada-data-gateway/what's-newRelease Notes
- https://www.zerodayinitiative.com/advisories/ZDI-23-1025/Third Party Advisory
- https://www.trianglemicroworks.com/products/scada-data-gateway/what's-newRelease Notes
- https://www.zerodayinitiative.com/advisories/ZDI-23-1025/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.