← Retour aux CVEs
CVE-2023-36610
MEDIUM5.9
Description
The affected TBox RTUs generate software security tokens using insufficient entropy. The random seed used to generate the software tokens is not initialized correctly, and other parts of the token are generated using predictable time-based values. An attacker with this knowledge could successfully brute force the token and authenticate themselves.
Details CVE
Score CVSS v3.15.9
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Vecteur d'attaqueNETWORK
ComplexiteHIGH
Privileges requisNONE
Interaction utilisateurNONE
Publie7/3/2023
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
ovarro:tbox_lt2ovarro:tbox_lt2_firmwareovarro:tbox_ms-cpu32ovarro:tbox_ms-cpu32-s2ovarro:tbox_ms-cpu32-s2_firmwareovarro:tbox_ms-cpu32_firmwareovarro:tbox_rm2ovarro:tbox_rm2_firmwareovarro:tbox_tg2ovarro:tbox_tg2_firmware
Faiblesses (CWE)
CWE-331
References
https://www.cisa.gov/news-events/ics-advisories/icsa-23-180-03(ics-cert@hq.dhs.gov)
https://www.cisa.gov/news-events/ics-advisories/icsa-23-180-03(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.