QID 591364

Date Published: 2023-04-03

QID 591364: Ovarro LT2 / RM2 / TG2 / CPU32 / CPU32-S2 Product Families Malicious Code Execution Vulnerability (TBOX-SA-2021-0006)

AFFECTED PRODUCTS
This vulnerability affects LT2 / RM2 / TG2 / CPU32 / CPU32-S2 product families in firmware 1.44 and earlier.

QID Detection Logic:
This QID checks for the Vulnerable version of Ovarro LT2 / RM2 / TG2 / CPU32 / CPU32-S2 product families using passive scanning.

An attacker may send and install malicious package to the TBox by using proprietary Modbus functions used for package update.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section TBOX-SA-2021-0006 for affected packages and patching details.

    CVEs related to QID 591364

    Software Advisories
    Advisory ID Software Component Link
    TBOX-SA-2021-0006 URL Logo www.ovarro.com/content-media/assigned/112144/TBOX-SA-2021-0006.pdf