CVE-2023-3395
—CVSS 3.1
6.5 medium
EPSS
<1%p25
Published
()
Modified
Description
All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, including sensitive information associated with document, such as password. The attacker could then obtain the plaintext password by using a memory viewer.
- Vendors
- ovarro
- Products
- tbox ms-cpu32 firmware, tbox ms-cpu32-s2 firmware, tbox lt2 firmware, tbox tg2 firmware, tbox rm2 firmware
- Weakness
- CWE-256, CWE-312
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.