HIGH · 7.2

CVE-2023-27389

Inadequate encryption strength vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker with an administrative privilege to apply a specially crafted Firmware update file...

Vulnerability Description

Inadequate encryption strength vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker with an administrative privilege to apply a specially crafted Firmware update file, alter the information, cause a denial-of-service (DoS) condition, and/or execute arbitrary code. The affected products and versions are as follows: M2M Gateway with the firmware Ver.3.7.10 and earlier (CPS-MG341-ADSC1-111, CPS-MG341-ADSC1-931, CPS-MG341G-ADSC1-111, CPS-MG341G-ADSC1-930, and CPS-MG341G5-ADSC1-931), M2M Controller Integrated Type with firmware Ver.3.7.6 and earlier versions (CPS-MC341-ADSC1-111, CPS-MC341-ADSC1-931, CPS-MC341-ADSC2-111, CPS-MC341G-ADSC1-110, CPS-MC341Q-ADSC1-111, CPS-MC341-DS1-111, CPS-MC341-DS11-111, CPS-MC341-DS2-911, and CPS-MC341-A1-111), and M2M Controller Configurable Type with firmware Ver.3.8.8 and earlier versions (CPS-MCS341-DS1-111, CPS-MCS341-DS1-131, CPS-MCS341G-DS1-130, CPS-MCS341G5-DS1-130, and CPS-MCS341Q-DS1-131).

CVSS Score

7.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ContecCps-Mg341-Adsc1-111 Firmware<= 3.7.10
ContecCps-Mg341-Adsc1-111-
ContecCps-Mg341-Adsc1-931 Firmware<= 3.7.10
ContecCps-Mg341-Adsc1-931-
ContecCps-Mg341G-Adsc1-111 Firmware<= 3.7.10
ContecCps-Mg341G-Adsc1-111-
ContecCps-Mg341G-Adsc1-930 Firmware<= 3.7.10
ContecCps-Mg341G-Adsc1-930-
ContecCps-Mg341G5-Adsc1-931 Firmware<= 3.7.10
ContecCps-Mg341G5-Adsc1-931-
ContecCps-Mc341-Adsc1-111 Firmware<= 3.7.6
ContecCps-Mc341-Adsc1-111-
ContecCps-Mc341-Adsc1-931 Firmware<= 3.7.6
ContecCps-Mc341-Adsc1-931-
ContecCps-Mc341-Adsc2-111 Firmware<= 3.7.6
ContecCps-Mc341-Adsc2-111-
ContecCps-Mc341G-Adsc1-110 Firmware<= 3.7.6
ContecCps-Mc341G-Adsc1-110-
ContecCps-Mc341Q-Adsc1-111 Firmware<= 3.7.6
ContecCps-Mc341Q-Adsc1-111-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-27389?

CVE-2023-27389 is a vulnerability with a CVSS score of 7.2 (HIGH). Inadequate encryption strength vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker with an administrative privilege to apply a specially crafted Firmware update file...

How severe is CVE-2023-27389?

CVE-2023-27389 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-27389?

Check the references section above for vendor advisories and patch information. Affected products include: Contec Cps-Mg341-Adsc1-111 Firmware, Contec Cps-Mg341-Adsc1-111, Contec Cps-Mg341-Adsc1-931 Firmware, Contec Cps-Mg341-Adsc1-931, Contec Cps-Mg341G-Adsc1-111 Firmware.