CVE-2023-46723

Source
https://cve.org/CVERecord?id=CVE-2023-46723
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-46723.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-46723
Aliases
  • GHSA-9qgg-ph2v-v4mh
Published
2023-10-31T15:34:44.646Z
Modified
2026-03-14T12:22:43.343261Z
Severity
  • 8.9 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L CVSS Calculator
Summary
lte-pic32-writer's sendto.txt may disclose URL and the API key
Details

lte-pic32-writer is a writer for PIC32 devices. In versions 0.0.1 and prior, those who use sendto.txt are vulnerable to attackers who known the IMEI reading the sendto.txt. The sendto.txt file can contain the SNS(such as slack and zulip) URL and API key. As of time of publication, a patch is not yet available. As workarounds, avoid using sendto.txt or use .htaccess to block access to sendto.txt.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/46xxx/CVE-2023-46723.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-538"
    ]
}
References

Affected packages

Git / github.com/paijp/lte-pic32-writer

Affected ranges

Type
GIT
Repo
https://github.com/paijp/lte-pic32-writer
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*
0.0.2
v0.*
v0.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-46723.json"