Attacker Impact
CVE-2023-3047 affects TMT Lockcell before version 15 and is scored critical by NVD [S1]. Public advisory sources describe unauthenticated SQL injection risk in the Lockcell login flow [S2][S3]. If an exposed deployment is affected, an attacker may bypass intended authentication or interact with backend database data, depending on deployment and privileges.
Root Cause
The issue is SQL injection caused by improper neutralization of user-supplied input before database query evaluation [S1]. Login input that changes SQL syntax can cross an authorization boundary when the affected Lockcell runtime is exposed.
Concrete Fixes
Upgrade TMT Lockcell to version 15 or newer [S1]. While rollout is in progress, restrict the Lockcell management UI to trusted networks, VPN, SSO, or an authenticated reverse proxy. Review authentication logs for unexpected activity, rotate credentials if unauthorized access is suspected, and verify normal invalid logins are denied after the patched runtime is deployed.
Covered by FixVibe
FixVibe's verified active scans flag TMT Lockcell login pages on your domain that show the SQL injection behavior described in this advisory, reported as a likely issue.
