ZDI-23-1032: (Pwn2Own) Triangle MicroWorks SCADA Data Gateway GTWWebMonitorService Unquoted Search Path Remote Code Execution Vulnerability
Published Aug 4, 2023
·Updated
This vulnerability allows remote attackers to execute code on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
1 affected component
Triangle MicroWorks SCADA Data Gateway
Event History
Aug 4, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Mar 26, 2025
Advisory Published
via ZDI·05:07 AM
Frequently Asked Questions
1
What is the severity of ZDI-23-1032?
The severity of ZDI-23-1032 is high due to the potential for remote code execution.
2
How do I fix ZDI-23-1032?
To fix ZDI-23-1032, apply the latest security patches released by Triangle MicroWorks for SCADA Data Gateway.
3
What systems are affected by ZDI-23-1032?
ZDI-23-1032 affects installations of Triangle MicroWorks SCADA Data Gateway.
4
Can ZDI-23-1032 be exploited without authentication?
No, ZDI-23-1032 requires authentication, but the authentication mechanism can be bypassed.
5
What kind of impact can ZDI-23-1032 have on systems?
ZDI-23-1032 can allow remote attackers to execute arbitrary code on affected systems.