Lucene search

K
nvd[email protected]NVD:CVE-2023-2003
HistoryJul 13, 2023 - 12:15 p.m.

CVE-2023-2003

2023-07-1312:15:09
CWE-506
web.nvd.nist.gov
1
embedded malicious code
remote attacker
base64-encoded
data tables
pcom protocol
device execution

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

52.1%

Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in the device’s data tables via the PCOM protocol, which can then be retrieved by a client and executed on the device.

Affected configurations

NVD
Node
unitronicsplcvision1210Match-
AND
unitronicsplcvision1210_firmwareMatch4.3build_5

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

52.1%

Related for NVD:CVE-2023-2003