CVE-2023-3395: Ovarro Tbox LT2 Firmware

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

​All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, including sensitive information associated with document, such as password. The attacker could then obtain the plaintext password by using a memory viewer.

Affected products

  • Ovarro Tbox LT2 Firmware: affected versions not specified
  • Ovarro Tbox Ms-CPU32-s2 Firmware: affected versions not specified
  • Ovarro Tbox Ms-CPU32 Firmware: affected versions not specified
  • Ovarro Tbox RM2 Firmware: affected versions not specified
  • Ovarro Tbox TG2 Firmware: affected versions not specified

Published 2023-07-03. Last modified 2026-06-17.