---
cve: "CVE-2023-22600"
severity: "CRITICAL"
cvss: 10.0
epss: "49%"
vendor: "InHand Networks"
kev: false
exploited: false
published: "2023-01-12 23:15:10"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T01:10:24+02:00"
---

# CVE-2023-22600

> 10.0 CRITICAL

## Beschreibung

InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-284: Improper Access Control. They allow unauthenticated devices to subscribe to MQTT topics on the same network as the device manager. An unauthorized user who knows of an existing topic name could send and receive messages to and from that topic. This includes the ability to send GET/SET configuration commands, reboot commands, and push firmware updates.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-284** — Improper Access Control
  The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

## Angriffsmuster (CAPEC)

- [CAPEC-19 — Embedding Scripts within Scripts](https://capec.mitre.org/data/definitions/19.html) _(Severity: High)_
- [CAPEC-441 — Malicious Logic Insertion](https://capec.mitre.org/data/definitions/441.html) _(Severity: High)_
- [CAPEC-478 — Modification of Windows Service Configuration](https://capec.mitre.org/data/definitions/478.html) _(Severity: High)_
- [CAPEC-479 — Malicious Root Certificate](https://capec.mitre.org/data/definitions/479.html) _(Severity: Low)_
- [CAPEC-502 — Intent Spoof](https://capec.mitre.org/data/definitions/502.html)
- [CAPEC-503 — WebView Exposure](https://capec.mitre.org/data/definitions/503.html)
- [CAPEC-536 — Data Injected During Configuration](https://capec.mitre.org/data/definitions/536.html) _(Severity: High)_
- [CAPEC-546 — Incomplete Data Deletion in a Multi-Tenant Environment](https://capec.mitre.org/data/definitions/546.html) _(Severity: Medium)_

## ATT&CK-Techniken

- [T1027.009 — Obfuscated Files or Information: Embedded Payloads](https://attack.mitre.org/techniques/T1027/009/)
- [T1546.004 — Event Triggered Execution:.bash_profile and .bashrc](https://attack.mitre.org/techniques/T1546/004/)
- [T1546.016 — Event Triggered Execution: Installer Packages](https://attack.mitre.org/techniques/T1546/016/)
- [T1574.011 — Hijack Execution Flow:Service Registry Permissions Weakness](https://attack.mitre.org/techniques/T1574/011/)
- [T1543.003 — Create or Modify System Process:Windows Service](https://attack.mitre.org/techniques/T1543/003/)
- [T1553.004 — Subvert Trust Controls:Install Root Certificate](https://attack.mitre.org/techniques/T1553/004/)

## Referenzen

- <https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-03>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-22600) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
