Weintek cMT3000 HMI Web CGI Stack-based Buffer Overflow
CVE-2023-43492
9.8CRITICAL
What is CVE-2023-43492?
The Weintek cMT3000 HMI Web CGI device is susceptible to a stack-based buffer overflow through the cgi-bin codesys.cgi. This vulnerability could enable an anonymous attacker to hijack control flow and bypass login authentication mechanisms, leading to unauthorized access to sensitive functionalities of the device.
Affected Version(s)
cMT-FHD 0 <= 20210210
cMT-HDM 0 <= 20210204
cMT3071 0 <= 20210218
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Hank Chen (PSIRT and Threat Research of TXOne Networks) reported these vulnerabilities to CISA.
