Cross-Site Scripting Vulnerability in Teltonika's Remote Management System
CVE-2023-2587

7.5HIGH

Key Information:

Vendor

Teltonika

Vendor
CVE Published:
22 May 2023

What is CVE-2023-2587?

Teltonika's Remote Management System versions prior to 4.10.0 are susceptible to a cross-site scripting (XSS) vulnerability found in the web interface's main page. An attacker possessing the MAC address and serial number of a connected device can exploit this vulnerability by sending a specially crafted JSON file containing an HTML object. Successful exploitation allows the attacker to execute arbitrary scripts within the account context, potentially leading to remote code execution on devices managed through this system. This security issue underscores the importance of applying the latest updates to safeguard against potential exploitation.

Affected Version(s)

Remote Management System 0 < 4.10.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Roni Gavrilov
OTORIO
.
CVE-2023-2587 : Cross-Site Scripting Vulnerability in Teltonika's Remote Management System