Weintek cMT3000 HMI Web CGI Stack-based Buffer Overflow
CVE-2023-38584

9.8CRITICAL

Key Information:

Vendor

Weintek

Status
Vendor
CVE Published:
19 October 2023

What is CVE-2023-38584?

A stack-based buffer overflow in the cgi-bin command_wb.cgi of Weintek's cMT3000 HMI Web CGI device allows anonymous attackers to exploit the vulnerability, potentially hijacking control flow. This could result in bypassing the login authentication process, exposing the device to unauthorized access and control.

Affected Version(s)

cMT-FHD 0 <= 20210210

cMT-HDM 0 <= 20210204

cMT3071 0 <= 20210218

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hank Chen (PSIRT and Threat Research of TXOne Networks) reported these vulnerabilities to CISA.
.