8.8

CVE-2023-32349

Version 00.07.03.4 and prior of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter parameters. However, variables for validation checks are stored in an external configuration file. An authenticated attacker could use an exposed UCI configuration utility to change these variables and enable malicious parameters in the dump utility, which could result in arbitrary code execution.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Teltonika-networksRut200 Firmware Version <= 00.07.03.4
   Teltonika-networksRut200 Version-
Teltonika-networksRut240 Firmware Version <= 00.07.03.4
   Teltonika-networksRut240 Version-
Teltonika-networksRut241 Firmware Version <= 00.07.03.4
   Teltonika-networksRut241 Version-
Teltonika-networksRut300 Firmware Version <= 00.07.03.4
   Teltonika-networksRut300 Version-
Teltonika-networksRut360 Firmware Version <= 00.07.03.4
   Teltonika-networksRut360 Version-
Teltonika-networksRut901 Firmware Version <= 00.07.03.4
   Teltonika-networksRut901 Version-
Teltonika-networksRut950 Firmware Version <= 00.07.03.4
   Teltonika-networksRut950 Version-
Teltonika-networksRut951 Firmware Version <= 00.07.03.4
   Teltonika-networksRut951 Version-
Teltonika-networksRut955 Firmware Version <= 00.07.03.4
   Teltonika-networksRut955 Version-
Teltonika-networksRut956 Firmware Version <= 00.07.03.4
   Teltonika-networksRut956 Version-
Teltonika-networksRutx08 Firmware Version <= 00.07.03.4
   Teltonika-networksRutx08 Version-
Teltonika-networksRutx09 Firmware Version <= 00.07.03.4
   Teltonika-networksRutx09 Version-
Teltonika-networksRutx10 Firmware Version <= 00.07.03.4
   Teltonika-networksRutx10 Version-
Teltonika-networksRutx11 Firmware Version <= 00.07.03.4
   Teltonika-networksRutx11 Version-
Teltonika-networksRutx12 Firmware Version <= 00.07.03.4
   Teltonika-networksRutx12 Version-
Teltonika-networksRutx14 Firmware Version >= 00.07.00 <= 00.07.03.4
   Teltonika-networksRutx14 Version-
Teltonika-networksRutx50 Firmware Version >= 00.07.00 <= 00.07.03.4
   Teltonika-networksRutx50 Version-
Teltonika-networksRutxr1 Firmware Version >= 00.07.00 <= 00.07.03.4
   Teltonika-networksRutxr1 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.203
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ics-cert@hq.dhs.gov 8 2.1 5.9
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-15 External Control of System or Configuration Setting

One or more system settings or configuration elements can be externally controlled by a user.