icon

We found results for “

CVE-2023-46723

Date: October 31, 2023

lte-pic32-writer is a writer for PIC32 devices. In versions 0.0.1 and prior, those who use "sendto.txt" are vulnerable to attackers who known the IMEI reading the sendto.txt. The sendto.txt file can contain the SNS(such as slack and zulip) URL and API key. As of time of publication, a patch is not yet available. As workarounds, avoid using "sendto.txt" or use ".htaccess" to block access to "sendto.txt".

Language: C++

Severity Score

Severity Score

Weakness Type (CWE)

Insertion of Sensitive Information into Externally-Accessible File or Directory

CWE-538

Insufficient Information

NVD-CWE-noinfo

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): LOW

Do you need more information?

Contact Us