Vulnerabilities > CVE-2023-32346 - Response Discrepancy Information Exposure vulnerability in Teltonika Remote Management System

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
teltonika
CWE-204

Summary

Teltonika’s Remote Management System versions prior to 4.10.0 contain a function that allows users to claim their devices. This function returns information based on whether the serial number of a device has already been claimed, the MAC address of a device has already been claimed, or whether the attempt to claim a device was successful. An attacker could exploit this to create a list of the serial numbers and MAC addresses of all devices cloud-connected to the Remote Management System.

Vulnerable Configurations

Part Description Count
Application
Teltonika
1

Common Weakness Enumeration (CWE)