IM
IronMonkey Threat Research

CVE-2023-2625 CRITICAL

Published: 2023-06-28 | Last Modified: 2024-11-21 | Status: Modified

Description

A vulnerability exists that can be exploited by an authenticated client that is connected to the same network segment as the CoreTec 4, having any level of access VIEWER to ADMIN. To exploit the vulnerability the attacker can inject shell commands through a particular field of the web user interface that will be executed by the system.

CVSS Metrics

Base Score: 8.0 (HIGH)

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack VectorADJACENT_NETWORK
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 2.1

Impact Score: 5.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-78
[email protected] Primary
en CWE-78

Affected Products

Vendor Product Version Update Type
abb txpert_hub_coretec_4_firmware * <built-in method update of dict object at 0x72a9cc5564c0> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:abb:txpert_hub_coretec_4_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:abb:txpert_hub_coretec_4:-:*:*:*:*:*:*:*
Notification
Message here