CVE-2023-3395

MEDIUM

TWinSoft Configuration Tool - Info Disclosure

Title source: llm
STIX 2.1

Description

​All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, including sensitive information associated with document, such as password. The attacker could then obtain the plaintext password by using a memory viewer.

Scores

CVSS v3 6.5
EPSS 0.0004
EPSS Percentile 13.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-312 CWE-256
Status published
Products (5)
ovarro/tbox_lt2_firmware
ovarro/tbox_ms-cpu32-s2_firmware
ovarro/tbox_ms-cpu32_firmware
ovarro/tbox_rm2_firmware
ovarro/tbox_tg2_firmware
Published Jul 03, 2023
Tracked Since Feb 18, 2026