CVE-2023-3395: Ovarro Tbox LT2 Firmware
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, including sensitive information associated with document, such as password. The attacker could then obtain the plaintext password by using a memory viewer.
Affected products
- Ovarro Tbox LT2 Firmware: affected versions not specified
- Ovarro Tbox Ms-CPU32-s2 Firmware: affected versions not specified
- Ovarro Tbox Ms-CPU32 Firmware: affected versions not specified
- Ovarro Tbox RM2 Firmware: affected versions not specified
- Ovarro Tbox TG2 Firmware: affected versions not specified
Published 2023-07-03. Last modified 2026-06-17.