A CWE-269: Improper Privilege Management vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow a local, low privileged attacker to elevate privileges to "manufacturer" level on the targeted system.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Telit
Subscribe
|
Bgs5
Subscribe
Bgs5 Firmware
Subscribe
Ehs5
Subscribe
Ehs5 Firmware
Subscribe
Ehs6
Subscribe
Ehs6 Firmware
Subscribe
Ehs8
Subscribe
Ehs8 Firmware
Subscribe
Els61
Subscribe
Els61 Firmware
Subscribe
Els81
Subscribe
Els81 Firmware
Subscribe
Pds5
Subscribe
Pds5 Firmware
Subscribe
Pds6
Subscribe
Pds6 Firmware
Subscribe
Pds8
Subscribe
Pds8 Firmware
Subscribe
Pls62
Subscribe
Pls62 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-51722 | A CWE-269: Improper Privilege Management vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow a local, low privileged attacker to elevate privileges to "manufacturer" level on the targeted system. |
Fixes
Solution
Telit Cinterion has released firmware updates to fix the issue. Contact Telit Cinterion for assistance.
Workaround
Enforce application signature verification to prohibit the installation of untrusted MIDlets on the device.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Kaspersky
Published:
Updated: 2024-08-02T21:09:37.384Z
Reserved: 2023-11-07T10:06:48.689Z
Link: CVE-2023-47611
No data.
Status : Modified
Published: 2023-11-10T17:15:07.380
Modified: 2024-11-21T08:30:31.177
Link: CVE-2023-47611
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD