In Weintek's cMT3000 HMI Web CGI device, the cgi-bin command_wb.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication.
No analysis available yet.
Vendor Solution
Weintek recommends users follow their Upgrade Instructions https://dl.weintek.com/public/Document/UM0/UM018010E_cMT_Series_OS_Update_Instructions_eng.pdf to update the following products to the latest versions: * cMT-FHD: OS version 20210211 * cMT-HDM: OS version 20210205 * cMT3071: OS version 20210219 * cMT3072: OS version 20210219 * cMT3103: OS version 20210219 * cMT3090: OS version 20210219 * cMT3151: OS version 20210219 For additional information, refer to Weintek's security bulletin https://dl.weintek.com/public/Document/TEC/TEC23005E_cMT_Web_Security_Update.pdf .
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-42383 | In Weintek's cMT3000 HMI Web CGI device, the cgi-bin command_wb.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication. |
Thu, 16 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T21:28:46.086Z
Reserved: 2023-09-20T14:26:47.021Z
Link: CVE-2023-38584
Updated: 2024-08-02T17:46:56.458Z
Status : Modified
Published: 2023-10-19T20:15:09.047
Modified: 2024-11-21T08:13:52.743
Link: CVE-2023-38584
No data.
OpenCVE Enrichment
No data.
EUVD