« Volver al listado

CVE-2023-47615

Estado: ModificadaMedia (5.5)—

A CWE-526: Exposure of Sensitive Information Through Environmental Variables vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow a local, low privileged attacker to get access to a sensitive data on the targeted system.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (10)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-47615",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-47615",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-03T19:33:54.319079Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "vulnerability@kaspersky.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.3,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "vulnerability@kaspersky.com",
      "affectedData": [
        {
          "vendor": "Telit Cinterion",
          "product": "BGS5",
          "defaultStatus": "affected"
        },
        {
          "vendor": "Telit Cinterion",
          "product": "EHS5",
          "defaultStatus": "affected"
        },
        {
          "vendor": "Telit Cinterion",
          "product": "EHS6",
          "defaultStatus": "affected"
        },
        {
          "vendor": "Telit Cinterion",
          "product": "EHS8",
          "defaultStatus": "affected"
        },
        {
          "vendor": "Telit Cinterion",
          "product": "PDS5",
          "defaultStatus": "affected"
        },
        {
          "vendor": "Telit Cinterion",
          "product": "PDS6",
          "defaultStatus": "affected"
        },
        {
          "vendor": "Telit Cinterion",
          "product": "PDS8",
          "defaultStatus": "affected"
        },
        {
          "vendor": "Telit Cinterion",
          "product": "ELS61",
          "defaultStatus": "affected"
        },
        {
          "vendor": "Telit Cinterion",
          "product": "ELS81",
          "defaultStatus": "affected"
        },
        {
          "vendor": "Telit Cinterion",
          "product": "PLS62",
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2023-11-09T13:15:07.500",
  "references": [
    {
      "url": "https://ics-cert.kaspersky.com/advisories/2023/11/09/klcert-22-212-telit-cinterion-thales-gemalto-modules-exposure-of-sensitive-information-through-environmental-variables/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vulnerability@kaspersky.com"
    },
    {
      "url": "https://ics-cert.kaspersky.com/advisories/2023/11/09/klcert-22-212-telit-cinterion-thales-gemalto-modules-exposure-of-sensitive-information-through-environmental-variables/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vulnerability@kaspersky.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-526"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A CWE-526: Exposure of Sensitive Information Through Environmental Variables vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow a local, low privileged attacker to get access to a sensitive data on the targeted system."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad CWE-526: Exposición de información confidencial a través de variables ambientales en Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 que podría permitir una vulnerabilidad local, un atacante con pocos privilegios para obtener acceso a datos confidenciales en el sistema objetivo."
    }
  ],
  "lastModified": "2026-06-17T06:32:58.683",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:telit:bgs5_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "236A82FB-6772-43F5-BFE5-378A6F740A25"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:telit:bgs5:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "ACE7A300-7A40-49FB-95A3-4F75796A6DB1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:telit:ehs5_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C33F8018-2AA2-4AA2-B97A-FB848F5D1C06"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:telit:ehs5:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5E937F19-944A-4D76-AF25-488FD30FABBB"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:telit:ehs6_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EEA2FCCD-752B-4DAB-8353-EF1B35AB143F"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:telit:ehs6:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "57219468-C424-43D0-98C0-A85A250AB733"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:telit:ehs8_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C74BE72-65CB-4DF3-8AE3-EBCFCD640BFD"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:telit:ehs8:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "691F7CF3-B36D-4440-A8A8-A4863FD5E828"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:telit:pds5_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1969DA7-72FC-4981-A3D5-A7919AA5D774"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:telit:pds5:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1F563DF9-B922-4FCF-8078-EA354F0ED5B5"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:telit:pds6_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "70E71C87-3011-43DB-ADB0-A926C7A8E87A"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:telit:pds6:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "EB6E32F2-2723-43B9-A730-22BCF9D420B0"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:telit:pds8_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1418767F-34D5-41A0-82BB-BBA7575DD21D"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:telit:pds8:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6F08EFD2-855A-498D-B88E-59414317BBFC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:telit:els61_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B580262-9CF7-4FE4-99E6-F3486A498F10"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:telit:els61:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DEEA5EE5-4F4A-4684-A15E-13AD8D553D3B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:telit:els81_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AAAC546F-9F47-4AFC-93EF-9261BFCE9ECB"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:telit:els81:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "BE8E98E9-4BB6-48E5-89ED-420653101A2C"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:telit:pls62_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A4647F52-2F3E-45F3-BD84-B54950A06AC8"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:telit:pls62:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AF3DBFD6-1C3D-4A8B-B458-E85DE4AF86BF"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vulnerability@kaspersky.com"
}