CVE-2023-43492

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
19/10/2023
Last modified:
30/10/2023

Description

<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> In Weintek&amp;#39;s cMT3000 HMI Web CGI device, the cgi-bin codesys.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication.<br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:weintek:cmt-fhd_firmware:*:*:*:*:*:*:*:* 20210212 (excluding)
cpe:2.3:h:weintek:cmt-fhd:-:*:*:*:*:*:*:*
cpe:2.3:o:weintek:cmt-hdm_firmware:*:*:*:*:*:*:*:* 20210206 (excluding)
cpe:2.3:h:weintek:cmt-hdm:-:*:*:*:*:*:*:*
cpe:2.3:o:weintek:cmt3071_firmware:*:*:*:*:*:*:*:* 20210220 (excluding)
cpe:2.3:h:weintek:cmt3071:-:*:*:*:*:*:*:*
cpe:2.3:o:weintek:cmt3072_firmware:*:*:*:*:*:*:*:* 20210220 (excluding)
cpe:2.3:h:weintek:cmt3072:-:*:*:*:*:*:*:*
cpe:2.3:o:weintek:cmt3090_firmware:*:*:*:*:*:*:*:* 20210220 (excluding)
cpe:2.3:h:weintek:cmt3090:-:*:*:*:*:*:*:*
cpe:2.3:o:weintek:cmt3103_firmware:*:*:*:*:*:*:*:* 20210220 (excluding)
cpe:2.3:h:weintek:cmt3103:-:*:*:*:*:*:*:*
cpe:2.3:o:weintek:cmt3151_firmware:*:*:*:*:*:*:*:* 20210220 (excluding)
cpe:2.3:h:weintek:cmt3151:-:*:*:*:*:*:*:*