Tbox Lt2 532 Firmware
by Ovarro
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-22648 | Hig | 0.57 | 8.8 | 0.01 | Jul 28, 2022 | Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file. | ||
| CVE-2021-22646 | Hig | 0.57 | 8.8 | 0.01 | Jul 28, 2022 | The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code execution. | ||
| CVE-2021-22650 | Hig | 0.49 | 7.5 | 0.01 | Jul 28, 2022 | An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWinSoft, which could lead to code execution. | ||
| CVE-2021-22644 | Hig | 0.49 | 7.5 | 0.01 | Jul 28, 2022 | Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key. | ||
| CVE-2021-22642 | Hig | 0.49 | 7.5 | 0.01 | Jul 28, 2022 | An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system. | ||
| CVE-2021-22640 | Hig | 0.49 | 7.5 | 0.01 | Jul 28, 2022 | An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks. |
- risk 0.57cvss 8.8epss 0.01
Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file.
- risk 0.57cvss 8.8epss 0.01
The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code execution.
- risk 0.49cvss 7.5epss 0.01
An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWinSoft, which could lead to code execution.
- risk 0.49cvss 7.5epss 0.01
Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key.
- risk 0.49cvss 7.5epss 0.01
An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system.
- risk 0.49cvss 7.5epss 0.01
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.