Tbox ms-cpu32 firmware
This hub aggregates every CVE we track for Tbox ms-cpu32 firmware, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
12
CVEs tracked
0
Critical
7
High
0
In CISA KEV
Severity distribution
HIGH7MEDIUM5
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 12 most recently published vulnerabilities affecting Tbox ms-cpu32 firmware.
- CVE-2023-3395 All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, inc...6.5
- CVE-2023-36611 The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could allow an attacker with “user” privileges to access files requiring higher pr...6.5
- CVE-2023-36610 The affected TBox RTUs generate software security tokens using insufficient entropy. The random seed used to generate the software tokens is not initialized correctly, and other parts of the to...5.9
- CVE-2023-36609 The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpenVPN server and push a malicious script onto the TBox ho...7.2
- CVE-2023-36608 The affected TBox RTUs store hashed passwords using MD5 encryption, which is an insecure encryption algorithm.6.5
- CVE-2023-36607CVE-2023-366075.3
- CVE-2021-22646Ovarro TBox Code Injection8.8
- CVE-2021-22644Ovarro TBox Use of Hard-coded Cryptographic Key7.5
- CVE-2021-22648Ovarro TBox Incorrect Permission Assignment for Critical Resource8.8
- CVE-2021-22650Ovarro TBox Relative Path Traversal7.5
- CVE-2021-22640Ovarro TBox Insufficiently Protected Credentials7.5
- CVE-2021-22642Ovarro TBox Uncontrolled Resource Consumption7.5
Product normalization is registry-driven with AI assist and human review. How it works