← Back to home
ICSA-23-061-02  ·  Published 2023-03-02  ·  View on CISA ICS-CERT ↗

Baicells Nova

CVSS 9.8 CRITICAL

Risk Summary

Successful exploitation of this vulnerability could allow commands performed using pre-login execution and with root permissions.

CVEs (1)

Remediations

  • Baicells has resolved this vulnerability in software version QRTB 2.12.8 and later. Baicells recommends all users currently running an earlier version of QRTB firmware upgrade affected products to the 2.12.8 firmware version. Firmware can be downloaded from the Baicells community page or upgraded via OMC.
  • Baicells published a security vulnerability notice for this issue.

Affected Vendors

Baicells Technologies

Affected Products (4)

Baicells Technologies · Nova 436Q <=QRTB_2.12.7
Baicells Technologies · Nova 430E <=QRTB_2.12.7
Baicells Technologies · Nova 430I <=QRTB_2.12.7
Baicells Technologies · Neutrino 430 <=QRTB_2.12.7

Affected Sectors

Communications

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more