Weintek cMT3092X
Summary
CISA has issued an alert regarding critical vulnerabilities in Weintek cMT3092X firmware and EasyWeb software. Successful exploitation could allow a non-privileged user to escalate privileges or view user credentials.
IFF Assessment
The identified vulnerabilities allow for privilege escalation and credential viewing, posing a direct threat to system security and user data.
Severity
The CVSS v3 score of 8.8 indicates a high severity. This is likely due to factors such as an easy attack vector (e.g., local access), the ability to escalate privileges, and potential for unauthorized access to sensitive information like credentials.
Defender Context
Defenders should prioritize patching affected Weintek cMT3092X devices and EasyWeb software to mitigate the risk of privilege escalation and credential theft. Monitoring for unusual cookie manipulation or unauthorized privilege changes on these industrial control systems is also crucial.