PT-2023-21090 · T&D+1 · Wdr-3+7
Junnosuke Kushibiki
+5
·
Publicado
2023-05-23
·
Atualizado
2025-01-31
·
CVE-2023-27388
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
T&D Corporation data logger products versions TR-71W/72W all firmware versions
T&D Corporation data logger products versions RTR-5W all firmware versions
T&D Corporation data logger products versions WDR-7 all firmware versions
T&D Corporation data logger products versions WDR-3 all firmware versions
T&D Corporation data logger products versions WS-2 all firmware versions
ESPEC MIC CORP. data logger products versions RT-12N/RS-12N all firmware versions
ESPEC MIC CORP. data logger products versions RT-22BN all firmware versions
ESPEC MIC CORP. data logger products versions TEU-12N all firmware versions
Description
An improper authentication issue in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered user.
Recommendations
For T&D Corporation data logger products versions TR-71W/72W all firmware versions, consider disabling remote access until a patch is available.
For T&D Corporation data logger products versions RTR-5W all firmware versions, restrict access to the product to minimize the risk of exploitation.
For T&D Corporation data logger products versions WDR-7 all firmware versions, avoid using default or weak passwords for registered users.
For T&D Corporation data logger products versions WDR-3 all firmware versions, limit the number of login attempts to prevent brute-force attacks.
For T&D Corporation data logger products versions WS-2 all firmware versions, implement additional authentication mechanisms, such as two-factor authentication.
For ESPEC MIC CORP. data logger products versions RT-12N/RS-12N all firmware versions, consider changing default passwords and restricting access to the product.
For ESPEC MIC CORP. data logger products versions RT-22BN all firmware versions, disable any unnecessary features or services that could be exploited.
For ESPEC MIC CORP. data logger products versions TEU-12N all firmware versions, monitor user activity and login attempts to detect potential exploitation.
Correção
Incorrect Authorization
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Rt-12N/Rs-12N
Rt-22Bn
Rtr-5W
Teu-12N
Tr-71W/72W
Wdr-3
Wdr-7
Ws-2