Vulnerabilities > CVE-2023-36609 - Inclusion of Functionality from Untrusted Control Sphere vulnerability in Ovarro products
Attack vector
NETWORK Attack complexity
LOW Privileges required
HIGH Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpenVPN server and push a malicious script onto the TBox host to acquire root privileges.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 7 | |
Hardware | 5 |