lte-pic32-writer is a writer for PIC32 devices. In versions 0.0.1 and prior, those who use `sendto.txt` are vulnerable to attackers who known the IMEI reading the sendto.txt. The sendto.txt file can contain the SNS(such as slack and zulip) URL and API key. As of time of publication, a patch is not yet available. As workarounds, avoid using `sendto.txt` or use `.htaccess` to block access to `sendto.txt`.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-50906 lte-pic32-writer is a writer for PIC32 devices. In versions 0.0.1 and prior, those who use `sendto.txt` are vulnerable to attackers who known the IMEI reading the sendto.txt. The sendto.txt file can contain the SNS(such as slack and zulip) URL and API key. As of time of publication, a patch is not yet available. As workarounds, avoid using `sendto.txt` or use `.htaccess` to block access to `sendto.txt`.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-09-05T20:14:13.094Z

Reserved: 2023-10-25T14:30:33.750Z

Link: CVE-2023-46723

cve-icon Vulnrichment

Updated: 2024-08-02T20:53:21.321Z

cve-icon NVD

Status : Modified

Published: 2023-10-31T16:15:10.233

Modified: 2024-11-21T08:29:09.297

Link: CVE-2023-46723

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.