PT-2023-9114 · Telit · Telit Cinterion Ehs5/6/8+3

Alexander Kozlov

+1

·

Published

2023-11-08

·

Updated

2023-11-16

·

CVE-2023-47614

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Telit Cinterion BGS5 Telit Cinterion EHS5/6/8 Telit Cinterion PDS5/6/8 Telit Cinterion ELS61/81 Telit Cinterion PLS62
Description The issue is related to the exposure of sensitive information. Exploitation of this issue may allow an attacker to obtain information about hidden virtual paths and file names on the targeted system. A local, low-privileged attacker could disclose this sensitive information.
Recommendations For Telit Cinterion BGS5, consider restricting access to sensitive information until a patch is available. For Telit Cinterion EHS5/6/8, avoid using hidden virtual paths and file names in sensitive operations until the issue is resolved. For Telit Cinterion PDS5/6/8, restrict access to the system to minimize the risk of exploitation. For Telit Cinterion ELS61/81, consider disabling access to sensitive files and paths until a fix is provided. For Telit Cinterion PLS62, limit the privileges of local attackers to prevent disclosure of sensitive information. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03900
CVE-2023-47614

Affected Products

Telit Cinterion Bgs5
Telit Cinterion Ehs5/6/8
Telit Cinterion Els61/81
Telit Cinterion Pls62