CVE-2023-47610

moderate-risk
Published 2023-11-09

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists in Telit Cinterion EHS5/6/8 that could allow a remote unauthenticated attacker to execute arbitrary code on the targeted system by sending a specially crafted SMS message.

Do I need to act?

~
2.8% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.1/10 High
NETWORK / HIGH complexity

Affected Products (10)

Bgs5 Firmware
Ehs5 Firmware
Ehs6 Firmware
Ehs8 Firmware
Pds5 Firmware
Pds6 Firmware
Pds8 Firmware
Els61 Firmware
Els81 Firmware
Pls62 Firmware

Affected Vendors

46
/ 100
moderate-risk
Severity 24/34 · High
Exploitability 6/34 · Minimal
Exposure 16/34 · Moderate