Input validation error in TELTONIKA products - CVE-2023-32349

 

Input validation error in TELTONIKA products - CVE-2023-32349

Published: May 15, 2023


Vulnerability identifier: #VU76156
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32349
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the system.

The vulnerability exists due to insufficient validation of user-supplied input within the filter parameters. A remote user on the local network can enable malicious parameters in the dump utility and execute arbitrary code on the target system.


Affected software

RUT200
RUT850
RUT360
RUT901
RUT300
RUT950
RUT241
RUT951
RUT240
RUT955
RUT230
RUT956

How to mitigate CVE-2023-32349

Install updates from vendor's website.

RUT200 - update to 00.07.04.1
RUT850 - update to 00.07.04.1
RUT360 - update to 00.07.04.1
RUT901 - update to 00.07.04.1
RUT300 - update to 00.07.04.1
RUT950 - update to 00.07.04.1
RUT241 - update to 00.07.04.1
RUT951 - update to 00.07.04.1
RUT240 - update to 00.07.04.1
RUT955 - update to 00.07.04.1
RUT230 - update to 00.07.04.1
RUT956 - update to 00.07.04.1

External References

Related Security Bulletins