ZeroHour

CVE-2023-36607

CVSS 3.1
5.3 medium
EPSS
<1%p41
Published
()
Modified
Description

The affected TBox RTUs are missing authorization for running some API commands. An attacker running these commands could reveal sensitive information such as software versions and web server file contents.

Vendors
ovarro
Products
tbox ms-cpu32 firmware, tbox ms-cpu32-s2 firmware, tbox lt2 firmware, tbox tg2 firmware, tbox rm2 firmware
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.