ID

VAR-202308-0867


CVE

CVE-2023-39462


TITLE

Triangle MicroWorks  of  SCADA Data Gateway  Vulnerability in unlimited upload of dangerous types of files in

Trust: 0.8

sources: JVNDB: JVNDB-2023-029200

DESCRIPTION

Triangle MicroWorks SCADA Data Gateway Workspace Unrestricted Upload Vulnerability. This vulnerability allows remote attackers to upload arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of workspace files. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this in conjunction with other vulnerabilitites to execute arbitrary code in the context of root. Was ZDI-CAN-20536. It is primarily used for data acquisition and monitoring in industrial automation control systems. Detailed vulnerability details are not currently available

Trust: 2.88

sources: NVD: CVE-2023-39462 // JVNDB: JVNDB-2023-029200 // ZDI: ZDI-23-1030 // CNVD: CNVD-2025-21061 // VULMON: CVE-2023-39462

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-21061

AFFECTED PRODUCTS

vendor:triangle microworksmodel:scada data gatewayscope: - version: -

Trust: 1.5

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:5.1.3.20324

Trust: 1.0

vendor:triangle microworksmodel:scada data gatewayscope:eqversion:5.1.3.20324

Trust: 0.8

vendor:triangle microworksmodel:scada data gatewayscope:eqversion: -

Trust: 0.8

vendor:trianglemodel:microworks scada data gatewayscope: - version: -

Trust: 0.6

sources: ZDI: ZDI-23-1030 // CNVD: CNVD-2025-21061 // JVNDB: JVNDB-2023-029200 // NVD: CVE-2023-39462

CVSS

SEVERITY

CVSSV2

CVSSV3

zdi-disclosures@trendmicro.com: CVE-2023-39462
value: MEDIUM

Trust: 1.0

OTHER: JVNDB-2023-029200
value: MEDIUM

Trust: 0.8

ZDI: CVE-2023-39462
value: MEDIUM

Trust: 0.7

CNVD: CNVD-2025-21061
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2025-21061
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:C/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

zdi-disclosures@trendmicro.com: CVE-2023-39462
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.0

Trust: 1.0

OTHER: JVNDB-2023-029200
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

ZDI: CVE-2023-39462
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.0

Trust: 0.7

sources: ZDI: ZDI-23-1030 // CNVD: CNVD-2025-21061 // JVNDB: JVNDB-2023-029200 // NVD: CVE-2023-39462

PROBLEMTYPE DATA

problemtype:CWE-434

Trust: 1.0

problemtype:Unlimited uploads of dangerous types of files (CWE-434) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2023-029200 // NVD: CVE-2023-39462

PATCH

title:Triangle MicroWorks has issued an update to correct this vulnerability.url:https://www.trianglemicroworks.com/products/scada-data-gateway/what's-new

Trust: 0.7

title:Patch for Triangle MicroWorks SCADA Data Gateway File Upload Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/731081

Trust: 0.6

sources: ZDI: ZDI-23-1030 // CNVD: CNVD-2025-21061

EXTERNAL IDS

db:NVDid:CVE-2023-39462

Trust: 4.0

db:ZDIid:ZDI-23-1030

Trust: 3.2

db:JVNDBid:JVNDB-2023-029200

Trust: 0.8

db:ZDI_CANid:ZDI-CAN-20536

Trust: 0.7

db:CNVDid:CNVD-2025-21061

Trust: 0.6

db:VULMONid:CVE-2023-39462

Trust: 0.1

sources: ZDI: ZDI-23-1030 // CNVD: CNVD-2025-21061 // VULMON: CVE-2023-39462 // JVNDB: JVNDB-2023-029200 // NVD: CVE-2023-39462

REFERENCES

url:https://www.trianglemicroworks.com/products/scada-data-gateway/what's-new

Trust: 2.5

url:https://www.zerodayinitiative.com/advisories/zdi-23-1030/

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2023-39462

Trust: 0.8

sources: ZDI: ZDI-23-1030 // CNVD: CNVD-2025-21061 // VULMON: CVE-2023-39462 // JVNDB: JVNDB-2023-029200 // NVD: CVE-2023-39462

CREDITS

Claroty Research - Team82 - Uri Katz, Noam Moshe, Vera Mens, Sharon Brizinov

Trust: 0.7

sources: ZDI: ZDI-23-1030

SOURCES

db:ZDIid:ZDI-23-1030
db:CNVDid:CNVD-2025-21061
db:VULMONid:CVE-2023-39462
db:JVNDBid:JVNDB-2023-029200
db:NVDid:CVE-2023-39462

LAST UPDATE DATE

2025-10-16T23:48:19.785000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-23-1030date:2023-08-04T00:00:00
db:CNVDid:CNVD-2025-21061date:2025-09-11T00:00:00
db:JVNDBid:JVNDB-2023-029200date:2025-06-19T01:31:00
db:NVDid:CVE-2023-39462date:2025-06-17T21:03:33.927

SOURCES RELEASE DATE

db:ZDIid:ZDI-23-1030date:2023-08-04T00:00:00
db:CNVDid:CNVD-2025-21061date:2025-09-11T00:00:00
db:JVNDBid:JVNDB-2023-029200date:2025-06-19T00:00:00
db:NVDid:CVE-2023-39462date:2024-05-03T03:15:11.533