Vulnerability Description
lte-pic32-writer is a writer for PIC32 devices. In versions 0.0.1 and prior, those who use `sendto.txt` are vulnerable to attackers who known the IMEI reading the sendto.txt. The sendto.txt file can contain the SNS(such as slack and zulip) URL and API key. As of time of publication, a patch is not yet available. As workarounds, avoid using `sendto.txt` or use `.htaccess` to block access to `sendto.txt`.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pajip | Lte-Pic32-Writer | < 0.0.3 |
Related Weaknesses (CWE)
References
- https://github.com/paijp/lte-pic32-writer/security/advisories/GHSA-9qgg-ph2v-v4mVendor Advisory
- https://github.com/paijp/lte-pic32-writer/security/advisories/GHSA-9qgg-ph2v-v4mVendor Advisory
FAQ
What is CVE-2023-46723?
CVE-2023-46723 is a vulnerability with a CVSS score of 8.9 (HIGH). lte-pic32-writer is a writer for PIC32 devices. In versions 0.0.1 and prior, those who use `sendto.txt` are vulnerable to attackers who known the IMEI reading the sendto.txt. The sendto.txt file can c...
How severe is CVE-2023-46723?
CVE-2023-46723 has been rated HIGH with a CVSS base score of 8.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-46723?
Check the references section above for vendor advisories and patch information. Affected products include: Pajip Lte-Pic32-Writer.