On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an...
Vulnerability Description
On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker could use this vulnerability to spam the logged-in user with false events.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-2187
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Philippe Laulheret
References
More from Triangle MicroWorks
View All →Affected Vendor
Triangle MicroWorks
View all reports →