CVE-2023-32349
CVSS V2 None
CVSS V3 None
Description
Versions 00.07.00 through 00.07.03.4 of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter parameters. However, variables for validation checks are stored in an external configuration file. An authenticated attacker could use an exposed UCI configuration utility to change these variables and enable malicious parameters in the dump utility, which could result in arbitrary code execution.
Overview
- CVE ID
- CVE-2023-32349
- Assigner
- ics-cert@hq.dhs.gov
- Vulnerability Status
- Awaiting Analysis
- Published Version
- 2023-05-22T16:15:10
- Last Modified Date
- 2023-05-22T16:15:51
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-08 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-32349 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32349 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-05-22 17:01:38 | Added to TrackCVE | |||
2023-05-22 17:01:41 | Weakness Enumeration | new |