Weintek cMT3000 HMI Web CGI Stack-based Buffer Overflow
CVE-2023-43492

9.8CRITICAL

Key Information:

Vendor

Weintek

Status
Vendor
CVE Published:
19 October 2023

What is CVE-2023-43492?

The Weintek cMT3000 HMI Web CGI device is susceptible to a stack-based buffer overflow through the cgi-bin codesys.cgi. This vulnerability could enable an anonymous attacker to hijack control flow and bypass login authentication mechanisms, leading to unauthorized access to sensitive functionalities of the device.

Affected Version(s)

cMT-FHD 0 <= 20210210

cMT-HDM 0 <= 20210204

cMT3071 0 <= 20210218

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hank Chen (PSIRT and Threat Research of TXOne Networks) reported these vulnerabilities to CISA.
.