ZeroHour

CVE-2023-3395

CVSS 3.1
6.5 medium
EPSS
<1%p25
Published
()
Modified
Description

​All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, including sensitive information associated with document, such as password. The attacker could then obtain the plaintext password by using a memory viewer.

Vendors
ovarro
Products
tbox ms-cpu32 firmware, tbox ms-cpu32-s2 firmware, tbox lt2 firmware, tbox tg2 firmware, tbox rm2 firmware
Weakness
CWE-256, CWE-312
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.