Vulnerability Description
Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in the device's data tables via the PCOM protocol, which can then be retrieved by a client and executed on the device.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Unitronics | Vision1210 Firmware | 4.3 |
| Unitronics | Vision1210 | - |
Related Weaknesses (CWE)
References
- https://www.hackplayers.com/2023/07/vulnerabilidad-vision1210-unitronics.htmlThird Party Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso-sci/embedded-malicious-code-vThird Party Advisory
- https://www.hackplayers.com/2023/07/vulnerabilidad-vision1210-unitronics.htmlThird Party Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso-sci/embedded-malicious-code-vThird Party Advisory
FAQ
What is CVE-2023-2003?
CVE-2023-2003 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in the device's data tab...
How severe is CVE-2023-2003?
CVE-2023-2003 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-2003?
Check the references section above for vendor advisories and patch information. Affected products include: Unitronics Vision1210 Firmware, Unitronics Vision1210.