CVE-2023-39464: (Pwn2Own) Triangle MicroWorks SCADA Data Gateway GTWWebMonitorService Unquoted Search Path Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute code on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the configuration of the GTWWebMonitorService service. The path to the service executable contains spaces not surrounded by quotations. An attacker can leverage this vulnerability to execute arbitrary code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-39464?
CVE-2023-39464 is considered a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2023-39464?
To fix CVE-2023-39464, apply the latest security patches released by Triangle MicroWorks for the SCADA Data Gateway.
Who is affected by CVE-2023-39464?
CVE-2023-39464 affects installations of Triangle MicroWorks SCADA Data Gateway.
Can CVE-2023-39464 be exploited without authentication?
While authentication is required to exploit CVE-2023-39464, the vulnerability allows for the bypassing of the existing authentication mechanism.
What type of vulnerability is CVE-2023-39464 classified as?
CVE-2023-39464 is classified as a remote code execution vulnerability.