Vulnerability Details CVE-2023-3395
All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, including sensitive information associated with document, such as password. The attacker could then obtain the plaintext password by using a memory viewer.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 10.5%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2023-3395
-
cpe:2.3:h:ovarro:tbox_lt2:-
-
cpe:2.3:h:ovarro:tbox_ms-cpu32-s2:-
-
cpe:2.3:h:ovarro:tbox_ms-cpu32:-
-
cpe:2.3:h:ovarro:tbox_rm2:-
-
cpe:2.3:h:ovarro:tbox_tg2:-
-
cpe:2.3:o:ovarro:tbox_lt2_firmware:-
-
cpe:2.3:o:ovarro:tbox_ms-cpu32-s2_firmware:-
-
cpe:2.3:o:ovarro:tbox_ms-cpu32_firmware:-
-
cpe:2.3:o:ovarro:tbox_rm2_firmware:-
-
cpe:2.3:o:ovarro:tbox_tg2_firmware:-