CVE-2023-36610 describes a medium-severity vulnerability (CVSS 5.9) affecting various Ovarro TBox RTU models, including the LT2, MS-CPU32, and RM2 series. The flaw stems from insufficient entropy in the generation of software security tokens, making them predictable due to incorrectly initialized random seeds and time-based values. An unauthenticated attacker could exploit this by brute-forcing tokens to gain unauthorized access, leading to high confidentiality impact. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.50.598CPE matchmatch criteria | cpe:2.3:o:ovarro:tbox_ms-cpu32_firmware:*:*:*:*:*:*:*:* | ||
<= 1.50.598CPE matchmatch criteria | cpe:2.3:o:ovarro:tbox_ms-cpu32-s2_firmware:*:*:*:*:*:*:*:* | ||
<= 1.50.598CPE matchmatch criteria | cpe:2.3:o:ovarro:tbox_lt2_firmware:*:*:*:*:*:*:*:* | ||
<= 1.50.598CPE matchmatch criteria | cpe:2.3:o:ovarro:tbox_tg2_firmware:*:*:*:*:*:*:*:* | ||
<= 1.50.598CPE matchmatch criteria | cpe:2.3:o:ovarro:tbox_rm2_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.