ZeroHour

CVE-2017-12733

CVSS 3.0
9.8 critical
EPSS
2%p83
Published
()
Modified
Description

A Missing Authentication for Critical Function issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versions: older than V175, V175-V189, V191-V195, and V16Q3.1. An attacker may create an application user account to gain administrative privileges.

Vendors
opwglobal
Products
sitesentinel isite atg firmware, sitesentinel integra 500 firmware, sitesentinel integra 100 firmware
Weakness
CWE-306
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.