Vulnerability Details CVE-2023-2187
On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker could use this vulnerability to spam the logged-in user with false events.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.6%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2023-2187
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.24
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.29
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.39
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.41.0213
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.42
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.48
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.50
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.50.0309
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.51
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.53
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0515
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0516
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0517
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0518
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0528
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0529
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0536
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0540
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0544
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0545
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0552
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0553
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0558
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0561
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0562
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0564
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0565
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0566
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0567
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0569
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0570
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0571
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0572
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0573
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0574
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0575
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0576
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0577
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0578
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0579
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0580
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0581
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0582
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0583
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0584
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0586
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0587
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0588
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0589
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0590
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0591
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0592
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0594
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0595
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0596
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0597
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0598
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:2.54.0599
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:3.00
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:3.00.0612
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:3.00.0615
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:3.00.0616
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:3.00.0630
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:3.00.0633
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:3.01.661
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:3.01.673
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:3.03.729
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:3.03.782
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:3.03.849
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:3.04.0025
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:3.05
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:3.06.0027
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:4.0.122
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:4.0.123
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:4.00.0123
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:4.00.0140
-
cpe:2.3:a:trianglemicroworks:scada_data_gateway:5.01.03