Vulnerability Description
All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, including sensitive information associated with document, such as password. The attacker could then obtain the plaintext password by using a memory viewer.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ovarro | Tbox Ms-Cpu32 Firmware | - |
| Ovarro | Tbox Ms-Cpu32 | - |
| Ovarro | Tbox Ms-Cpu32-S2 Firmware | - |
| Ovarro | Tbox Ms-Cpu32-S2 | - |
| Ovarro | Tbox Lt2 Firmware | - |
| Ovarro | Tbox Lt2 | - |
| Ovarro | Tbox Tg2 Firmware | - |
| Ovarro | Tbox Tg2 | - |
| Ovarro | Tbox Rm2 Firmware | - |
| Ovarro | Tbox Rm2 | - |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-180-03MitigationThird Party AdvisoryUS Government Resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-180-03MitigationThird Party AdvisoryUS Government Resource
FAQ
What is CVE-2023-3395?
CVE-2023-3395 is a vulnerability with a CVSS score of 6.5 (MEDIUM). All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, includin...
How severe is CVE-2023-3395?
CVE-2023-3395 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-3395?
Check the references section above for vendor advisories and patch information. Affected products include: Ovarro Tbox Ms-Cpu32 Firmware, Ovarro Tbox Ms-Cpu32, Ovarro Tbox Ms-Cpu32-S2 Firmware, Ovarro Tbox Ms-Cpu32-S2, Ovarro Tbox Lt2 Firmware.