ZDI-23-1031: (Pwn2Own) Triangle MicroWorks SCADA Data Gateway Trusted Certification Unrestricted Upload of File Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1031?
The severity of ZDI-23-1031 is high due to its potential for remote code execution.
How do I fix ZDI-23-1031?
To fix ZDI-23-1031, apply the latest security patches provided by Triangle MicroWorks for the SCADA Data Gateway.
What versions of Triangle MicroWorks SCADA Data Gateway are affected by ZDI-23-1031?
ZDI-23-1031 affects all versions of Triangle MicroWorks SCADA Data Gateway prior to the security updates.
What are the risks of not addressing ZDI-23-1031?
Not addressing ZDI-23-1031 can lead to unauthorized remote code execution, compromising system integrity and security.
Is authentication sufficient to prevent ZDI-23-1031 exploitation?
No, the existing authentication mechanism can be bypassed, making reliance on it insufficient to prevent exploitation.