PT-2023-22670 · Garo · Garo Wallbox

CVE-2023-30399

·

Published

2023-05-04

·

Updated

2023-05-12

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GARO Wallbox GLB/GTB/GTC versions prior to v189
Description The issue concerns insecure permissions in the settings page, allowing attackers to redirect users to a crafted update package link via a man-in-the-middle attack.
Recommendations For versions prior to v189, update to version v189 or later to resolve the issue. As a temporary workaround, consider restricting access to the settings page to minimize the risk of exploitation.

Exploit

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-30399

Affected Products

Garo Wallbox