CVE-2023-36609

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Jul 3, 2023
Updated: Jul 10, 2023
CWE ID 829

Summary

CVE-2023-36609 is a vulnerability affecting TBox RTUs that utilize OpenVPN with root privileges. An attacker can establish a local OpenVPN server and push a malicious script onto the TBox host, exploiting this weakness to gain root access. This issue poses a significant risk, as the attacker could then take full control of the affected device. To mitigate this vulnerability, it is recommended to configure OpenVPN with non-root privileges and implement strict access controls for user-defined scripts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share