Severe Vulnerabilities in Cinterion Cellular Modems Pose Risks to Various Industries
ID: e48d3faf-0c28-5c89-81b4-57a0c5dff950
STIX ID: report--e48d3faf-0c28-5c89-81b4-57a0c5dff950
Feed Name: The Hacker News
Cybersecurity researchers (Kaspersky ICS CERT) disclosed eight vulnerabilities in Cinterion cellular modems — most notably CVE-2023-47610, a heap overflow enabling remote code execution via SMS — affecting multiple Cinterion models (BGS5, EHS5/6/7, PDS5/6/8, ELS61/81, PLS62). The flaws include privilege escalation, path traversal, and sensitive-data exposure and could allow attackers to take full control of modems embedded in critical IoT systems; recommended mitigations include disabling non-essential SMS, using private APNs, restricting physical access, and applying security audits/updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
