Tbox ms-cpu32
This hub aggregates every CVE we track for Tbox ms-cpu32, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
ICS / OT / IoTother
6
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM5HIGH1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 6 most recently published vulnerabilities affecting Tbox ms-cpu32.
- CVE-2023-3395 All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, inc...6.5
- CVE-2023-36611 The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could allow an attacker with “user” privileges to access files requiring higher pr...6.5
- CVE-2023-36610 The affected TBox RTUs generate software security tokens using insufficient entropy. The random seed used to generate the software tokens is not initialized correctly, and other parts of the to...5.9
- CVE-2023-36609 The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpenVPN server and push a malicious script onto the TBox ho...7.2
- CVE-2023-36608 The affected TBox RTUs store hashed passwords using MD5 encryption, which is an insecure encryption algorithm.6.5
- CVE-2023-36607CVE-2023-366075.3
Product normalization is registry-driven with AI assist and human review. How it works