CVE-2023-32348: SSRF
Teltonika’s Remote Management System versions prior to 4.10.0 contain a virtual private network (VPN) hub feature for cross-device communication that uses OpenVPN. It connects new devices in a manner that allows the new device to communicate with all Teltonika devices connected to the VPN. The OpenVPN server also allows users to route through it. An attacker could route a connection to a remote server through the OpenVPN server, enabling them to scan and access data from other Teltonika devices connected to the VPN.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32348?
CVE-2023-32348 has been classified as a high severity vulnerability affecting Teltonika's Remote Management System.
How do I fix CVE-2023-32348?
To fix CVE-2023-32348, upgrade the Teltonika Remote Management System to version 4.10.0 or later.
What types of devices are affected by CVE-2023-32348?
CVE-2023-32348 affects all versions of Teltonika's Remote Management System prior to 4.10.0.
What functionality does the CVE-2023-32348 vulnerability impact?
CVE-2023-32348 impacts the VPN hub feature used for cross-device communication, allowing unauthorized access to connected devices.
Is CVE-2023-32348 related to other vulnerabilities?
Yes, CVE-2023-32348 is related to several other vulnerabilities affecting Teltonika's Remote Management System, including CVE-2023-32346 and CVE-2023-32347.