PT-2023-17403 · Unknown · Vision1210
Carlos Antonini Cepeda
·
Published
2023-07-13
·
Updated
2026-01-08
·
CVE-2023-2003
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vision1210 version 4.3 build 5
Description
The issue allows a remote attacker to store base64-encoded malicious code in the device's data tables via the PCOM protocol. This malicious code can then be retrieved by a client and executed on the device.
Recommendations
For Vision1210 version 4.3 build 5, consider restricting access to the PCOM protocol to minimize the risk of exploitation until a patch is available. As a temporary workaround, disabling the execution of code retrieved from the device's data tables can help mitigate the issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vision1210