7.2

CVE-2023-36609

The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpenVPN server and push a malicious script onto the TBox host to acquire root privileges.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OvarroTbox Ms-cpu32 Firmware Version <= 1.50.598
   OvarroTbox Ms-cpu32 Version-
OvarroTbox Ms-cpu32-s2 Firmware Version <= 1.50.598
   OvarroTbox Ms-cpu32-s2 Version-
OvarroTbox Lt2 Firmware Version <= 1.50.598
   OvarroTbox Lt2 Version-
OvarroTbox Tg2 Firmware Version <= 1.50.598
   OvarroTbox Tg2 Version-
OvarroTbox Rm2 Firmware Version <= 1.50.598
   OvarroTbox Rm2 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.214
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
ics-cert@hq.dhs.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-829 Inclusion of Functionality from Untrusted Control Sphere

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.