CVE-2023-36610

CVSS V2 None CVSS V3 None
Description
​The affected TBox RTUs generate software security tokens using insufficient entropy. The random seed used to generate the software tokens is not initialized correctly, and other parts of the token are generated using predictable time-based values. An attacker with this knowledge could successfully brute force the token and authenticate themselves.
Overview
  • CVE ID
  • CVE-2023-36610
  • Assigner
  • icscert
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-07-03T20:01:31.978Z
  • Last Modified Date
  • 2023-07-03T20:01:31.978Z
References
Reference URL Reference Tags
https://www.cisa.gov/news-events/ics-advisories/icsa-23-180-03 government-resource
History
Created Old Value New Value Data Type Notes
2024-06-25 16:58:38 Added to TrackCVE