Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-2586

Опубликовано: 22 мая 2023
Источник: nvd
CVSS3: 9
CVSS3: 9.8
EPSS Низкий

Описание

Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices through the RMS platform. If the user has not disabled the "RMS management feature" enabled by default, then an attacker could register that device to themselves. This could enable the attacker to perform different operations on the user's devices, including remote code execution with 'root' privileges (using the 'Task Manager' feature on RMS).

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:teltonika:remote_management_system:4.14.0:*:*:*:*:*:*:*

EPSS

Процентиль: 69%
0.00587
Низкий

9 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9
github
больше 2 лет назад

Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices through the RMS platform. If the user has not disabled the "RMS management feature" enabled by default, then an attacker could register that device to themselves. This could enable the attacker to perform different operations on the user's devices, including remote code execution with 'root' privileges (using the 'Task Manager' feature on RMS).

EPSS

Процентиль: 69%
0.00587
Низкий

9 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-287