The affected TBox RTUs are missing authorization for running some API commands. An attacker running these commands could reveal sensitive information such as software versions and web server file contents.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-23-180-03 | government resource mitigation third party advisory us government resource |