CVE-2023-46723 is a high-severity information disclosure vulnerability affecting pajip lte_pic32_writer versions 0.0.1 and prior. Attackers who know a device's IMEI can read the sendto.txt file, which may contain sensitive SNS URLs and API keys. The vulnerability has a CVSS score of 7.5 (High) due to its network-based attack vector and high confidentiality impact, requiring no user interaction. There is currently no patch available, but workarounds include avoiding sendto.txt or blocking access via .htaccess. This CVE is not actively exploited, lacks public exploit code, and has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.0.3CPE matchmatch criteria | cpe:2.3:a:pajip:lte-pic32-writer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.