Asea Brown Boveri Terra AC wallbox products information disclosure | CVE-2023-0864

NAME
__________
Asea Brown Boveri Terra AC wallbox products information disclosure

Platforms Affected:
Asea Brown Boveri Terra AC wallbox 1.2.7 Symbiosis CE
Asea Brown Boveri Terra AC wallbox 1.6.5 Terra AC MID CE
Asea Brown Boveri Terra AC wallbox 1.6.5 Terra AC Juno CE CE
Asea Brown Boveri Terra AC wallbox 1.5.25 Terra AC PTB CE
Asea Brown Boveri Terra AC wallbox 1.5.5 UL40/80A
Asea Brown Boveri Terra AC wallbox 1.6.5 UL32A
Asea Brown Boveri Terra AC wallbox 1.6.5 JP

Risk Level:
7.1

Exploitability:
Unproven

Consequences:
Obtain Information

DESCRIPTION
__________

Asea Brown Boveri Terra AC wallbox products could allow a remote attacker to obtain sensitive information, caused by the transmission of configured credentials in plain text. By sniffing the network traffic during authentication, an attacker could exploit this vulnerability to obtain user credentials. An attacker could use this information to sending a specially crafted message to the system node, allowing the attacker to execute actions and modify or read configuration settings of the product.

CVSS 3.0 Information
__________

Privileges Required:
None

User Interaction:
Required

Scope:
Unchanged

Access Vector:
Adjacent Network


 


A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

Buy Me A Coffee
Patreon

 To keep up to date follow us on the below channels.

join
Telegram
discord
Discord
reddit
Reddit
linkedin
LinkedIn