AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-2187

MEDIUM · CVSS 5.3 EPSS 0.59%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-06-07 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2023-2187
Severity
MEDIUM
CVSS
5.3
EPSS
0.59%

Original NVD Description

On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker could use this vulnerability to spam the logged-in user with false events.