CVE-2023-36610

CVSS Score of 10 (low)

Details

Published Jul 3, 2023
Updated: Nov 7, 2023
CWE ID 331

Summary

CVE-2023-36610 is a vulnerability that affects the TBox RTUs. These RTUs generate software security tokens using insufficient entropy, as the random seed used for token generation is not initialized correctly and other parts of the token are generated using predictable time-based values. This flaw could allow an attacker to successfully brute force the token and authenticate themselves. The vulnerability has a CVSS score of 5.9, indicating a medium severity level with high potential for confidentiality impact. To remediate this vulnerability, it is recommended to update the affected products with a patch or version that addresses the entropy issue in software token generation.

Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2023-36610 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions