CVE-2023-46102
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Oct 25, 2023
Updated: Nov 6, 2023
CWE ID 798
Summary
CVE-2023-46102: The Android Client application in the AppHub server utilizes an encrypted MQTT protocol for remote device management. However, the protocol employs a hard-coded DES symmetric key for encryption, which can be obtained by reverse engineering both the client application and the server-side web application. Malicious actors on the same network as the HMI device can control a rogue MQTT broker, enabling them to craft deceitful messages and execute arbitrary commands on the vulnerable device.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share