Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, which could result in obtaining remote control of the crash report server.



Advisories
Source ID Title
EUVD EUVD EUVD-2023-58060 Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, which could result in obtaining remote control of the crash report server.
Fixes

Solution

Weintek recommends users apply the following mitigations: * Update EasyBuilder Pro to v6.08.01.614 https://www.weintek.com/globalw/Download/Download.aspx * Update EasyBuilder Pro to v6.08.02.500 https://www.weintek.com/globalw/Download/Download.aspx


Workaround

No workaround given by the vendor.

History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T21:26:49.870Z

Reserved: 2023-10-25T22:32:36.999Z

Link: CVE-2023-5777

cve-icon Vulnrichment

Updated: 2024-08-02T08:07:32.769Z

cve-icon NVD

Status : Modified

Published: 2023-11-06T20:15:08.033

Modified: 2024-11-21T08:42:28.023

Link: CVE-2023-5777

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.