CVE-2023-27389 is a high-severity vulnerability (CVSS 7.2) affecting CONPROSYS IoT Gateway products, specifically M2M Gateways, M2M Controllers Integrated Type, and M2M Controllers Configurable Type running older firmware versions. The flaw stems from inadequate encryption strength (CWE-326), allowing a remote authenticated attacker with administrative privileges to upload a malicious firmware update. This can lead to data alteration, denial-of-service, or arbitrary code execution on the affected devices. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.7.10CPE matchmatch criteria | cpe:2.3:o:contec:cps-mg341-adsc1-111_firmware:*:*:*:*:*:*:*:* | ||
<= 3.7.10CPE matchmatch criteria | cpe:2.3:o:contec:cps-mg341-adsc1-931_firmware:*:*:*:*:*:*:*:* | ||
<= 3.7.10CPE matchmatch criteria | cpe:2.3:o:contec:cps-mg341g-adsc1-111_firmware:*:*:*:*:*:*:*:* | ||
<= 3.7.10CPE matchmatch criteria | cpe:2.3:o:contec:cps-mg341g-adsc1-930_firmware:*:*:*:*:*:*:*:* | ||
<= 3.7.10CPE matchmatch criteria | cpe:2.3:o:contec:cps-mg341g5-adsc1-931_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.