PT-2023-9114 · Telit · Telit Cinterion Ehs5/6/8+3
Alexander Kozlov
+1
·
Published
2023-11-08
·
Updated
2023-11-16
·
CVE-2023-47614
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Telit Cinterion BGS5
Telit Cinterion EHS5/6/8
Telit Cinterion PDS5/6/8
Telit Cinterion ELS61/81
Telit Cinterion PLS62
Description
The issue is related to the exposure of sensitive information. Exploitation of this issue may allow an attacker to obtain information about hidden virtual paths and file names on the targeted system. A local, low-privileged attacker could disclose this sensitive information.
Recommendations
For Telit Cinterion BGS5, consider restricting access to sensitive information until a patch is available.
For Telit Cinterion EHS5/6/8, avoid using hidden virtual paths and file names in sensitive operations until the issue is resolved.
For Telit Cinterion PDS5/6/8, restrict access to the system to minimize the risk of exploitation.
For Telit Cinterion ELS61/81, consider disabling access to sensitive files and paths until a fix is provided.
For Telit Cinterion PLS62, limit the privileges of local attackers to prevent disclosure of sensitive information.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telit Cinterion Bgs5
Telit Cinterion Ehs5/6/8
Telit Cinterion Els61/81
Telit Cinterion Pls62