PT-2023-9109 · Telit · Telit Cinterion Ehs5/6/8+3

Alexander Kozlov

+1

·

Published

2023-11-08

·

Updated

2024-05-13

·

CVE-2023-47611

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Telit Cinterion BGS5 Telit Cinterion EHS5/6/8 Telit Cinterion PDS5/6/8 Telit Cinterion ELS61/81 Telit Cinterion PLS62
Description A vulnerability exists in the Telit Cinterion software that is related to improper privilege management. This issue could allow a local, low-privileged attacker to elevate privileges to the "manufacturer" level on the targeted system. The exploitation of this vulnerability may enable an attacker to gain higher privileges in the system.
Recommendations For Telit Cinterion BGS5, consider restricting access to sensitive areas of the system until a patch is available. For Telit Cinterion EHS5/6/8, restrict privileges to the lowest level necessary for operation to minimize the risk of exploitation. For Telit Cinterion PDS5/6/8, avoid using the system with low-privileged access until the issue is resolved. For Telit Cinterion ELS61/81, limit system access to trusted users only as a temporary workaround. For Telit Cinterion PLS62, disable any non-essential features that may be exploited to elevate privileges until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2024-03894
CVE-2023-47611

Affected Products

Telit Cinterion Bgs5
Telit Cinterion Ehs5/6/8
Telit Cinterion Els61/81
Telit Cinterion Pls62