Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file.
Solution:
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-21-054-04 | third party advisory us government resource |