CVE-2023-2003 is a critical embedded malicious code vulnerability affecting Unitronics Vision1210 devices running operating system version 4.3, build 5. A remote attacker can exploit this by storing base64-encoded malicious code in the device's data tables via the PCOM protocol. This malicious code can then be retrieved and executed on the device by a client. With a CVSS score of 9.8 (CRITICAL), this vulnerability has a network attack vector, low attack complexity, and requires no user interaction, leading to high impacts on confidentiality, integrity, and availability. The FAUCET Risk Score is 92/100, indicating a severe threat. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion is minimal, with only one mention, and there has been no media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.3CPE matchmatch criteria | cpe:2.3:o:unitronics:vision1210_firmware:4.3:build_5:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.