PT-2023-9111 · Telit · Telit Cinterion Ehs5/6/8+3
Alexander Kozlov
+1
·
Published
2023-11-09
·
Updated
2023-11-16
·
CVE-2023-47615
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Telit Cinterion BGS5
Telit Cinterion EHS5/6/8
Telit Cinterion PDS5/6/8
Telit Cinterion ELS61/81
Telit Cinterion PLS62
Description
A vulnerability exists that could allow a local, low privileged attacker to get access to sensitive data on the targeted system through exposure of sensitive information via environmental variables. The exploitation of this vulnerability may permit an attacker to obtain protected information.
Recommendations
For Telit Cinterion BGS5, consider restricting access to sensitive environmental variables until a patch is available.
For Telit Cinterion EHS5/6/8, restrict access to sensitive data to minimize the risk of exploitation.
For Telit Cinterion PDS5/6/8, avoid using sensitive environmental variables in the affected system until the issue is resolved.
For Telit Cinterion ELS61/81, consider disabling access to sensitive information to prevent exploitation.
For Telit Cinterion PLS62, restrict access to protected data to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telit Cinterion Bgs5
Telit Cinterion Ehs5/6/8
Telit Cinterion Els61/81
Telit Cinterion Pls62