Description
Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability.

The specific flaw exists due to the lack of user authentication. The issue results from missing authentication in the default system configuration. An attacker can leverage this vulnerability to execute arbitrary code in the context of root. Was ZDI-CAN-20501.
Published: 2024-05-03
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-43180 Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. The specific flaw exists due to the lack of user authentication. The issue results from missing authentication in the default system configuration. An attacker can leverage this vulnerability to execute arbitrary code in the context of root. Was ZDI-CAN-20501.
History

Wed, 25 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 17 Jun 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Trianglemicroworks
Trianglemicroworks scada Data Gateway
CPEs cpe:2.3:a:trianglemicroworks:scada_data_gateway:5.1.3.20324:*:*:*:*:*:*:*
Vendors & Products Trianglemicroworks
Trianglemicroworks scada Data Gateway

Subscriptions

Trianglemicroworks Scada Data Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2024-08-02T18:10:20.768Z

Reserved: 2023-08-02T21:37:23.120Z

Link: CVE-2023-39457

cve-icon Vulnrichment

Updated: 2024-08-02T18:10:20.768Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-03T03:15:10.647

Modified: 2025-06-17T21:03:54.923

Link: CVE-2023-39457

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses