PT-2023-15946 · Toby-L220+4 · Toby-L220+4

CVE-2023-0011

·

Publicado

2023-12-20

·

Atualizado

2024-01-04

CVSS v3.1

7.6

Alta

VetorAV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOBY-L2 series: TOBY-L200, TOBY-L201, TOBY-L210, TOBY-L220, TOBY-L280
Description A flaw in the input validation in TOBY-L2 allows a user to execute arbitrary operating system commands using specifically crafted AT commands. This issue requires physical access to the serial interface of the module or the ability to modify the system or software which uses its serial interface to send malicious AT commands. Exploitation of the issue gives full administrative (root) privileges to the attacker to execute any operating system command on TOBY-L2, which can lead to modification of the behavior of the module itself as well as the components connected with it. It can further provide the ability to read system level files and hamper the availability of the module.
Recommendations For TOBY-L200, consider restricting access to the serial interface to minimize the risk of exploitation. For TOBY-L201, restrict the ability to send malicious AT commands until a fix is available. For TOBY-L210, limit the privileges of the attacker by implementing additional security measures. For TOBY-L220, avoid using the vulnerable input validation mechanism until a patch is released. For TOBY-L280, as a temporary workaround, consider disabling the ability to execute arbitrary operating system commands until a fix is available.

Correção

OS Command Injection

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-0011

Produtos afetados

Toby-L200
Toby-L201
Toby-L210
Toby-L220
Toby-L280