CVE-2023-36609

Publication date

2023-07-03 19:59:08

Family

icscert

State

PUBLISHED

Description

The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpenVPN server and push a malicious script onto the TBox host to acquire root privileges.