Remote Management System Vulnerability in Teltonika Products
CVE-2023-32346

5.3MEDIUM

Key Information:

Vendor

Teltonika

Vendor
CVE Published:
22 May 2023

What is CVE-2023-32346?

Teltonika’s Remote Management System prior to version 4.10.0 has a security weakness that allows users to claim devices. This flaw reveals details about whether the serial number or MAC address of a device has been previously claimed or if the claiming process was successful. An attacker leveraging this vulnerability could compile a comprehensive list of serial numbers and MAC addresses for all devices linked to the Remote Management System, potentially leading to unauthorized access or further attacks.

Affected Version(s)

Remote Management System 0 < 4.10.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Noam Moshe
Claroty
.