CVE-2023-36611: Ovarro Tbox LT2 Firmware
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could allow an attacker with “user” privileges to access files requiring higher privileges by establishing an SSH session and providing the other tokens.
Affected products
- Ovarro Tbox LT2 Firmware: up to and including 1.50.598
- Ovarro Tbox Ms-CPU32-s2 Firmware: up to and including 1.50.598
- Ovarro Tbox Ms-CPU32 Firmware: up to and including 1.50.598
- Ovarro Tbox RM2 Firmware: up to and including 1.50.598
- Ovarro Tbox TG2 Firmware: up to and including 1.50.598
Published 2023-07-03. Last modified 2026-06-17.