Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tbox Ms Cpu32 Firmware MEDIUM 6.5
CVE-2023-36611

The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could allow an attacker with “user” pri…

Fix: after 1.50.598
Fix from $1,600 2023-07-03
Tbox Ms Cpu32 Firmware MEDIUM 6.5
CVE-2023-3395

​All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open…

Mitigation only
Fix from $1,600 2023-07-03
Tbox Ms Cpu32 Firmware MEDIUM 5.9
CVE-2023-36610

​The affected TBox RTUs generate software security tokens using insufficient entropy. The random seed used to generate the software tokens is not ini…

Fix: after 1.50.598
Fix from $1,600 2023-07-03
Tbox Ms Cpu32 Firmware HIGH 7.2
CVE-2023-36609

The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpenVPN serv…

Fix: after 1.50.598
Fix from $1,950 2023-07-03
Tbox Ms Cpu32 Firmware MEDIUM 6.5
CVE-2023-36608

The affected TBox RTUs store hashed passwords using MD5 encryption, which is an insecure encryption algorithm.

Fix: after 1.50.598
Fix from $1,600 2023-07-03
Tbox Ms Cpu32 Firmware MEDIUM 5.3
CVE-2023-36607

The affected TBox RTUs are missing authorization for running some API commands. An attacker running these commands could reveal sensitive information…

Fix: after 1.50.598
Fix from $1,600 2023-06-29
Twinsoft CRITICAL 9.8
CVE-2021-22640

An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.

Fix: 1.46 / 12.4+
Fix from $2,300 2022-07-28
Twinsoft CRITICAL 9.8
CVE-2021-22644

Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key.

Fix: 1.46 / 12.4+
Fix from $2,300 2022-07-28
Twinsoft CRITICAL 9.8
CVE-2021-22646

The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code e…

Fix: 1.46 / 12.4+
Fix from $2,300 2022-07-28
Twinsoft CRITICAL 9.8
CVE-2021-22648

Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file.

Fix: 1.46 / 12.4+
Fix from $2,300 2022-07-28
Twinsoft CRITICAL 9.8
CVE-2021-22650

An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWinSoft, which could lead to cod…

Fix: 1.46 / 12.4+
Fix from $2,300 2022-07-28
Twinsoft HIGH 7.5
CVE-2021-22642

An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system.

Fix: 1.46 / 12.4+
Fix from $1,950 2022-07-28