Vulnerability Description
An issue was discovered in Qubo Smart Plug10A version HSP02_01_01_14_SYSTEM-10 A, allows local attackers to gain sensitive information and other unspecified impact via UART console.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Quboworld | Smart Plug 10A Firmware | hsp02_01_01_14_system-10_a |
| Quboworld | Smart Plug 10A | - |
References
- https://github.com/Yashodhanvivek/Qubo_smart_switch_security_assessment/blob/maiThird Party Advisory
- https://github.com/Yashodhanvivek/Qubo_smart_switch_security_assessment/blob/maiThird Party Advisory
FAQ
What is CVE-2023-36160?
CVE-2023-36160 is a vulnerability with a CVSS score of 5.5 (MEDIUM). An issue was discovered in Qubo Smart Plug10A version HSP02_01_01_14_SYSTEM-10 A, allows local attackers to gain sensitive information and other unspecified impact via UART console.
How severe is CVE-2023-36160?
CVE-2023-36160 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-36160?
Check the references section above for vendor advisories and patch information. Affected products include: Quboworld Smart Plug 10A Firmware, Quboworld Smart Plug 10A.