CVE-2023-2587

Teltonika’s Remote Management System versions prior to 4.10.0 contain a cross-site scripting (XSS) vulnerability in the main page of the web interface. An attacker with the MAC address and serial number of a connected device could send a maliciously crafted JSON file with an HTML object to trigger the vulnerability. This could allow the attacker to execute scripts in the account context and obtain remote code execution on managed devices.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-08 Third Party Advisory US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-08 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:teltonika:remote_management_system:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:58

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.3
v2 : unknown
v3 : 7.5
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-08 - Third Party Advisory, US Government Resource () https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-08 - Third Party Advisory, US Government Resource

27 May 2023, 03:31

Type Values Removed Values Added
CPE cpe:2.3:a:teltonika:remote_management_system:*:*:*:*:*:*:*:*
References (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-08 - (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-08 - Third Party Advisory, US Government Resource
First Time Teltonika remote Management System
Teltonika
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.3

Information

Published : 2023-05-22 16:15

Updated : 2024-11-21 07:58


NVD link : CVE-2023-2587

Mitre link : CVE-2023-2587

CVE.ORG link : CVE-2023-2587


JSON object : View

Products Affected

teltonika

  • remote_management_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')