PT-2023-9112 · Telit · Telit Cinterion Ehs5/6/8+3

Alexander Kozlov

+1

·

Published

2023-11-08

·

Updated

2023-11-16

·

CVE-2023-47612

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Telit Cinterion BGS5 Telit Cinterion EHS5/6/8 Telit Cinterion PDS5/6/8 Telit Cinterion ELS61/81 Telit Cinterion PLS62
Description A vulnerability exists that could allow an attacker with physical access to the target system to obtain read/write access to any files and directories on the targeted system, including hidden files and directories. This issue is related to the use of files and directories accessible to external parties.
Recommendations For Telit Cinterion BGS5, consider restricting access to sensitive files and directories to minimize the risk of exploitation. For Telit Cinterion EHS5/6/8, restrict access to critical system files to prevent unauthorized modifications. For Telit Cinterion PDS5/6/8, limit access to configuration files to reduce the risk of system compromise. For Telit Cinterion ELS61/81, restrict access to system directories to prevent unauthorized access. For Telit Cinterion PLS62, consider disabling access to sensitive system files until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03898
CVE-2023-47612

Affected Products

Telit Cinterion Bgs5
Telit Cinterion Ehs5/6/8
Telit Cinterion Els61/81
Telit Cinterion Pls62