HIGH · 8.1

CVE-2023-47610

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists in Telit Cinterion EHS5/6/8 that could allow a remote unauthenticated attacker to execute arbitrary code on the targeted syst...

Vulnerability Description

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists in Telit Cinterion EHS5/6/8 that could allow a remote unauthenticated attacker to execute arbitrary code on the targeted system by sending a specially crafted SMS message.

CVSS Score

8.1

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
TelitBgs5 Firmware-
TelitBgs5-
TelitEhs5 Firmware-
TelitEhs5-
TelitEhs6 Firmware-
TelitEhs6-
TelitEhs8 Firmware-
TelitEhs8-
TelitPds5 Firmware-
TelitPds5-
TelitPds6 Firmware-
TelitPds6-
TelitPds8 Firmware-
TelitPds8-
TelitEls61 Firmware-
TelitEls61-
TelitEls81 Firmware-
TelitEls81-
TelitPls62 Firmware-
TelitPls62-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-47610?

CVE-2023-47610 is a vulnerability with a CVSS score of 8.1 (HIGH). A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists in Telit Cinterion EHS5/6/8 that could allow a remote unauthenticated attacker to execute arbitrary code on the targeted syst...

How severe is CVE-2023-47610?

CVE-2023-47610 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-47610?

Check the references section above for vendor advisories and patch information. Affected products include: Telit Bgs5 Firmware, Telit Bgs5, Telit Ehs5 Firmware, Telit Ehs5, Telit Ehs6 Firmware.