CVE-2023-36607
—CVSS 3.1
5.3 medium
EPSS
<1%p41
Published
()
Modified
Description
The affected TBox RTUs are missing authorization for running some API commands. An attacker running these commands could reveal sensitive information such as software versions and web server file contents.
- Vendors
- ovarro
- Products
- tbox ms-cpu32 firmware, tbox ms-cpu32-s2 firmware, tbox lt2 firmware, tbox tg2 firmware, tbox rm2 firmware
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.