CVE-2023-36609
03.07.2023, 20:15
The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpenVPN server and push a malicious script onto the TBox host to acquire root privileges.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ovarro | tbox_ms-cpu32_firmware | 𝑥 ≤ 1.50.598 |
| ovarro | tbox_ms-cpu32-s2_firmware | 𝑥 ≤ 1.50.598 |
| ovarro | tbox_lt2_firmware | 𝑥 ≤ 1.50.598 |
| ovarro | tbox_tg2_firmware | 𝑥 ≤ 1.50.598 |
| ovarro | tbox_rm2_firmware | 𝑥 ≤ 1.50.598 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| ovarro | tbox_ms-cpu32 | 𝑥 ≤ 1.50.598 | ADP |
| ovarro | tbox_ms-cpu32-s2 | 𝑥 ≤ 1.50.598 | ADP |
| ovarro | tbox_tg2 | 𝑥 ≤ 1.50.598 | ADP |
| ovarro | tbox_lt2 | 𝑥 ≤ 1.50.598 | ADP |
| ovarro | tbox_rm2 | 𝑥 ≤ 1.50.598 | ADP |
Common Weakness Enumeration