PT-2023-9111 · Telit · Telit Cinterion Ehs5/6/8+3

Alexander Kozlov

+1

·

Published

2023-11-09

·

Updated

2023-11-16

·

CVE-2023-47615

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Telit Cinterion BGS5 Telit Cinterion EHS5/6/8 Telit Cinterion PDS5/6/8 Telit Cinterion ELS61/81 Telit Cinterion PLS62
Description A vulnerability exists that could allow a local, low privileged attacker to get access to sensitive data on the targeted system through exposure of sensitive information via environmental variables. The exploitation of this vulnerability may permit an attacker to obtain protected information.
Recommendations For Telit Cinterion BGS5, consider restricting access to sensitive environmental variables until a patch is available. For Telit Cinterion EHS5/6/8, restrict access to sensitive data to minimize the risk of exploitation. For Telit Cinterion PDS5/6/8, avoid using sensitive environmental variables in the affected system until the issue is resolved. For Telit Cinterion ELS61/81, consider disabling access to sensitive information to prevent exploitation. For Telit Cinterion PLS62, restrict access to protected data to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-03897
CVE-2023-47615

Affected Products

Telit Cinterion Bgs5
Telit Cinterion Ehs5/6/8
Telit Cinterion Els61/81
Telit Cinterion Pls62