Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-2625


A vulnerability exists that can be exploited by an authenticated client that is connected to the same network segment as the CoreTec 4, having any level of access VIEWER to ADMIN. To exploit the vulnerability the attacker can inject shell commands through a particular field of the web user interface that will be executed by the system.


Published

2023-06-28T17:15:10.627

Last Modified

2024-11-21T07:58:57.377

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.0 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-78
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System abb txpert_hub_coretec_4_firmware < 3.0.1 Yes
Hardware abb txpert_hub_coretec_4 - No

References