« Volver al listado

CVE-2023-39467

Estado: AnalizadaMedia (5.3)—

Triangle MicroWorks SCADA Data Gateway certificate Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the configuration of certificate web directory. The issue results from the exposure of sensitive information in the application webroot. An attacker can leverage this vulnerability to disclose sensitive information. Was ZDI-CAN-20798.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-39467",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-39467",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-05-07T19:22:23.242020Z"
        }
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "zdi-disclosures@trendmicro.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "zdi-disclosures@trendmicro.com",
      "affectedData": [
        {
          "vendor": "Triangle MicroWorks",
          "product": "SCADA Data Gateway",
          "versions": [
            {
              "status": "affected",
              "version": "5.1.3.20324"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:trianglemicroworks:scada_data_gateway:*:*:*:*:*:*:*:*"
          ],
          "vendor": "trianglemicroworks",
          "product": "scada_data_gateway",
          "versions": [
            {
              "status": "affected",
              "version": "5.1.3.20324"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-05-03T03:15:12.360",
  "references": [
    {
      "url": "https://www.trianglemicroworks.com/products/scada-data-gateway/what's-new",
      "tags": [
        "Release Notes"
      ],
      "source": "zdi-disclosures@trendmicro.com"
    },
    {
      "url": "https://www.zerodayinitiative.com/advisories/ZDI-23-1035/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "zdi-disclosures@trendmicro.com"
    },
    {
      "url": "https://www.trianglemicroworks.com/products/scada-data-gateway/what's-new",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.zerodayinitiative.com/advisories/ZDI-23-1035/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "zdi-disclosures@trendmicro.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-219"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Triangle MicroWorks SCADA Data Gateway certificate Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the configuration of certificate web directory. The issue results from the exposure of sensitive information in the application webroot. An attacker can leverage this vulnerability to disclose sensitive information. Was ZDI-CAN-20798."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de divulgación de información del certificado SCADA Data Gateway de Triangle MicroWorks. Esta vulnerabilidad permite a atacantes remotos revelar información confidencial sobre las instalaciones afectadas de Triangle MicroWorks SCADA Data Gateway. No se requiere autenticación para aprovechar esta vulnerabilidad. La falla específica existe en la configuración del directorio web del certificado. El problema se debe a la exposición de información confidencial en la raíz web de la aplicación. Un atacante puede aprovechar esta vulnerabilidad para revelar información confidencial. Era ZDI-CAN-20798."
    }
  ],
  "lastModified": "2026-06-17T06:12:23.677",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:trianglemicroworks:scada_data_gateway:5.1.3.20324:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3AC0B76-A64D-4650-AFF9-4B9AE5A8C4C3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "zdi-disclosures@trendmicro.com"
}