QID 591363

Date Published: 2023-04-03

QID 591363: Ovarro TBox MS-CPU32, TBox MS-CPU32-S2, TBox LT2, TBox TG2, TBox RM2 product families Vulnerability (TBOX-SA-2021-0005)

AFFECTED PRODUCTS
This vulnerability affects TBox MS-CPU32, TBox MS-CPU32-S2, TBox LT2, TBox TG2, TBox RM2 product families in version 1.45 and earlier of the firmware.

QID Detection Logic:
This QID checks for the Vulnerable version of Ovarro TBox using passive scanning.

The TBox may crash when receiving specially crafted Modbus packets.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Low - 0 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section TBOX-SA-2021-0005 for affected packages and patching details.

    CVEs related to QID 591363

    Software Advisories
    Advisory ID Software Component Link
    TBOX-SA-2021-0005 URL Logo www.ovarro.com/content-media/assigned/112143/TBOX-SA-2021-0005.pdf