The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpenVPN server and push a malicious script onto the TBox host to acquire root privileges.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-40554 | The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpenVPN server and push a malicious script onto the TBox host to acquire root privileges. |
Mon, 25 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-11-25T18:11:48.466Z
Reserved: 2023-06-23T20:39:08.361Z
Link: CVE-2023-36609
Updated: 2024-08-02T16:52:53.785Z
Status : Modified
Published: 2023-07-03T20:15:09.537
Modified: 2024-11-21T08:10:03.853
Link: CVE-2023-36609
No data.
OpenCVE Enrichment
No data.
EUVD