Vulnerability Description
In Weintek's cMT3000 HMI Web CGI device, an anonymous attacker can execute arbitrary commands after login to the device.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Weintek | Cmt-Fhd Firmware | < 20210212 |
| Weintek | Cmt-Fhd | - |
| Weintek | Cmt-Hdm Firmware | < 20210206 |
| Weintek | Cmt-Hdm | - |
| Weintek | Cmt3071 Firmware | < 20210220 |
| Weintek | Cmt3071 | - |
| Weintek | Cmt3072 Firmware | < 20210220 |
| Weintek | Cmt3072 | - |
| Weintek | Cmt3090 Firmware | < 20210220 |
| Weintek | Cmt3090 | - |
| Weintek | Cmt3103 Firmware | < 20210220 |
| Weintek | Cmt3103 | - |
| Weintek | Cmt3151 Firmware | < 20210220 |
| Weintek | Cmt3151 | - |
Related Weaknesses (CWE)
References
- https://dl.weintek.com/public/Document/TEC/TEC23005E_cMT_Web_Security_Update.pdfVendor Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-285-12Third Party AdvisoryUS Government Resource
- https://dl.weintek.com/public/Document/TEC/TEC23005E_cMT_Web_Security_Update.pdfVendor Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-285-12Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2023-40145?
CVE-2023-40145 is a vulnerability with a CVSS score of 8.8 (HIGH). In Weintek's cMT3000 HMI Web CGI device, an anonymous attacker can execute arbitrary commands after login to the device.
How severe is CVE-2023-40145?
CVE-2023-40145 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-40145?
Check the references section above for vendor advisories and patch information. Affected products include: Weintek Cmt-Fhd Firmware, Weintek Cmt-Fhd, Weintek Cmt-Hdm Firmware, Weintek Cmt-Hdm, Weintek Cmt3071 Firmware.