Input validation error in TELTONIKA products - CVE-2023-32349
Published: May 15, 2023
Vulnerability identifier: #VU76156
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32349
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to insufficient validation of user-supplied input within the filter parameters. A remote user on the local network can enable malicious parameters in the dump utility and execute arbitrary code on the target system.
Affected software
RUT200
RUT850
RUT360
RUT901
RUT300
RUT950
RUT241
RUT951
RUT240
RUT955
RUT230
RUT956
RUT850
RUT360
RUT901
RUT300
RUT950
RUT241
RUT951
RUT240
RUT955
RUT230
RUT956
How to mitigate CVE-2023-32349
Install updates from vendor's website.
RUT200 - update to 00.07.04.1
RUT850 - update to 00.07.04.1
RUT360 - update to 00.07.04.1
RUT901 - update to 00.07.04.1
RUT300 - update to 00.07.04.1
RUT950 - update to 00.07.04.1
RUT241 - update to 00.07.04.1
RUT951 - update to 00.07.04.1
RUT240 - update to 00.07.04.1
RUT955 - update to 00.07.04.1
RUT230 - update to 00.07.04.1
RUT956 - update to 00.07.04.1
RUT850 - update to 00.07.04.1
RUT360 - update to 00.07.04.1
RUT901 - update to 00.07.04.1
RUT300 - update to 00.07.04.1
RUT950 - update to 00.07.04.1
RUT241 - update to 00.07.04.1
RUT951 - update to 00.07.04.1
RUT240 - update to 00.07.04.1
RUT955 - update to 00.07.04.1
RUT230 - update to 00.07.04.1
RUT956 - update to 00.07.04.1