Lucene search

K
cveIcscertCVE-2023-2586
HistoryMay 22, 2023 - 4:15 p.m.

CVE-2023-2586

2023-05-2216:15:09
CWE-287
icscert
web.nvd.nist.gov
22
teltonika
remote management system
rms
unauthorized device registration
remote code execution
cve-2023-2586
nvd
vulnerability

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.002

Percentile

61.6%

Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices through the RMS platform. If the user has not disabled the “RMS management feature” enabled by default, then an attacker could register that device to themselves. This could enable the attacker to perform different operations on the user’s devices, including remote code execution with ‘root’ privileges (using the ‘Task Manager’ feature on RMS).

Affected configurations

Nvd
Node
teltonikaremote_management_systemMatch4.14.0
VendorProductVersionCPE
teltonikaremote_management_system4.14.0cpe:2.3:a:teltonika:remote_management_system:4.14.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Remote Management System",
    "vendor": "Teltonika",
    "versions": [
      {
        "lessThan": "4.14.0",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.002

Percentile

61.6%

Related for CVE-2023-2586