Telit designs embedded cellular and IoT modules and firmware widely deployed in connected devices and industrial equipment, despite a modestly scoped product line. Its vulnerability exposure centers on memory-safety issues such as buffer overflows, information-disclosure flaws including cleartext storage of credentials, and sensitive-data leakage pathways recurrent across its BGS5 and EHS firmware families, with an elevated tendency toward serious severity outcomes. Live exploitation activity and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Telit over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-47610CRITICAL A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists in Telit Cinterion EHS5/6/8 that could allow a remote unauthenticated attacker to execute arbitrary code | Nov 9, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-47611HIGH A CWE-269: Improper Privilege Management vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion | Nov 10, 2023 | 7.8 | 24 | NO | NO |
CVE-2023-47613HIGH A CWE-23: Relative Path Traversal vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 | Nov 9, 2023 | 7.1 | 22 | NO | NO |
CVE-2023-47612MEDIUM A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS | Nov 9, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-47615MEDIUM A CWE-526: Exposure of Sensitive Information Through Environmental Variables vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit | Nov 9, 2023 | 5.5 | 16 | NO | NO |
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinter | Nov 10, 2023 | 3.3 | 14 | NO | NO |
CVE-2023-47616MEDIUM A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinter | Nov 9, 2023 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Telit.
Media articles that mention a CVE ID that affects a product developed by Telit — matched by CVE ID, not by vendor name.