CVE-2023-39465
Triangle MicroWorks SCADA Data Gateway vulnerability analysis and mitigation

Overview

Triangle MicroWorks SCADA Data Gateway was found to contain a Use of Hard-coded Cryptographic Key Information Disclosure vulnerability (CVE-2023-39465). The vulnerability was discovered on April 6, 2023, and publicly disclosed on August 4, 2023. This vulnerability affects the TmwCrypto class in the SCADA Data Gateway software (ZDI Advisory).

Technical details

The vulnerability exists within the TmwCrypto class and stems from two critical issues: the usage of a hard-coded cryptographic key and the usage of a hard-coded certificate. The vulnerability has been assigned a CVSS v3.0 base score of 7.5 (HIGH) with the vector string: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating it is network-accessible, requires low attack complexity, and needs no privileges or user interaction to exploit (ZDI Advisory).

Impact

The vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. No authentication is required to exploit this vulnerability, making it particularly severe. The impact is limited to information disclosure, with no direct impact on system integrity or availability (ZDI Advisory).

Exploitability

The vulnerability can be exploited remotely without requiring any authentication or user interaction. The low attack complexity and lack of required privileges make this vulnerability highly exploitable. The vulnerability was discovered by Uri Katz of Claroty Team82 (ZDI Advisory).

Mitigation and workarounds

Triangle MicroWorks has released an update to address this vulnerability. Users are advised to upgrade to the latest version of the SCADA Data Gateway software. The fix was included in version 5.01.03, which specifically addresses vulnerability ICSA-22-249-01 (Triangle MicroWorks).

Additional resources


SourceThis report was generated using AI

Related Triangle MicroWorks SCADA Data Gateway vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-0369HIGH8.8
  • Triangle MicroWorks SCADA Data Gateway logoTriangle MicroWorks SCADA Data Gateway
  • cpe:2.3:a:trianglemicroworks:scada_data_gateway
NoYesMay 07, 2024
CVE-2023-39465HIGH7.5
  • Triangle MicroWorks SCADA Data Gateway logoTriangle MicroWorks SCADA Data Gateway
  • cpe:2.3:a:trianglemicroworks:scada_data_gateway
NoNoMay 03, 2024
CVE-2023-39468HIGH7.2
  • Triangle MicroWorks SCADA Data Gateway logoTriangle MicroWorks SCADA Data Gateway
  • cpe:2.3:a:trianglemicroworks:scada_data_gateway
NoNoMay 03, 2024
CVE-2023-39467MEDIUM5.3
  • Triangle MicroWorks SCADA Data Gateway logoTriangle MicroWorks SCADA Data Gateway
  • cpe:2.3:a:trianglemicroworks:scada_data_gateway
NoNoMay 03, 2024
CVE-2023-39466MEDIUM5.3
  • Triangle MicroWorks SCADA Data Gateway logoTriangle MicroWorks SCADA Data Gateway
  • cpe:2.3:a:trianglemicroworks:scada_data_gateway
NoNoMay 03, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management