In Weintek's cMT3000 HMI Web CGI device, the cgi-bin codesys.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication.
No analysis available yet.
Vendor Solution
Weintek recommends users follow their Upgrade Instructions https://dl.weintek.com/public/Document/UM0/UM018010E_cMT_Series_OS_Update_Instructions_eng.pdf to update the following products to the latest versions: * cMT-FHD: OS version 20210211 * cMT-HDM: OS version 20210205 * cMT3071: OS version 20210219 * cMT3072: OS version 20210219 * cMT3103: OS version 20210219 * cMT3090: OS version 20210219 * cMT3151: OS version 20210219 For additional information, refer to Weintek's security bulletin https://dl.weintek.com/public/Document/TEC/TEC23005E_cMT_Web_Security_Update.pdf .
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-47907 | In Weintek's cMT3000 HMI Web CGI device, the cgi-bin codesys.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication. |
Thu, 16 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T21:28:29.900Z
Reserved: 2023-09-20T14:26:47.014Z
Link: CVE-2023-43492
Updated: 2024-08-02T19:44:43.206Z
Status : Modified
Published: 2023-10-19T20:15:09.230
Modified: 2024-11-21T08:24:08.970
Link: CVE-2023-43492
No data.
OpenCVE Enrichment
No data.
EUVD