CVE-2023-39466: Triangle MicroWorks SCADA Data Gateway get_config Missing Authentication Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getconfig endpoint. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-39466?
CVE-2023-39466 has a high severity rating due to its potential for remote exploitation without authentication.
How do I fix CVE-2023-39466?
To fix CVE-2023-39466, apply the latest security patch provided by Triangle MicroWorks for SCADA Data Gateway.
What types of information can be disclosed due to CVE-2023-39466?
CVE-2023-39466 can potentially disclose sensitive configuration and operational information from the affected SCADA Data Gateway.
Does CVE-2023-39466 require authentication to exploit?
No, CVE-2023-39466 does not require authentication, making it more dangerous for affected installations.
Which software versions are affected by CVE-2023-39466?
CVE-2023-39466 affects specific versions of Triangle MicroWorks SCADA Data Gateway, details of which can be found in the vendor's advisories.