CRITICAL · 9.6

CVE-2023-29121

Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.

Vulnerability Description

Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.

CVSS Score

9.6

CRITICAL

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
EnelxWaybox Pro Firmware< 2.1.1.0_jb3vu096a
EnelxWaybox Pro3.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-29121?

CVE-2023-29121 is a vulnerability with a CVSS score of 9.6 (CRITICAL). Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.

How severe is CVE-2023-29121?

CVE-2023-29121 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2023-29121?

Check the references section above for vendor advisories and patch information. Affected products include: Enelx Waybox Pro Firmware, Enelx Waybox Pro.