CVE-2023-36607
29.06.2023, 21:15
The affected TBox RTUs are missing authorization for running some API commands. An attacker running these commands could reveal sensitive information such as software versions and web server file contents.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ovarro | tbox_ms-cpu32_firmware | 𝑥 ≤ 1.50.598 |
| ovarro | tbox_ms-cpu32-s2_firmware | 𝑥 ≤ 1.50.598 |
| ovarro | tbox_lt2_firmware | 𝑥 ≤ 1.50.598 |
| ovarro | tbox_tg2_firmware | 𝑥 ≤ 1.50.598 |
| ovarro | tbox_rm2_firmware | 𝑥 ≤ 1.50.598 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration