CVE-2023-36609
03.07.2023, 20:15
The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpenVPN server and push a malicious script onto the TBox host to acquire root privileges.Enginsight
Vendor | Product | Version |
---|---|---|
ovarro | tbox_ms-cpu32_firmware | 𝑥 ≤ 1.50.598 |
ovarro | tbox_ms-cpu32-s2_firmware | 𝑥 ≤ 1.50.598 |
ovarro | tbox_lt2_firmware | 𝑥 ≤ 1.50.598 |
ovarro | tbox_tg2_firmware | 𝑥 ≤ 1.50.598 |
ovarro | tbox_rm2_firmware | 𝑥 ≤ 1.50.598 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration