ZeroHour

CVE-2023-42769

CVSS 3.1
9.8 critical
EPSS
<1%p54
Published
()
Modified
Description

The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.

Vendors
sielco
Products
analog fm transmitter exc5000gx firmware, analog fm transmitter exc120gx firmware, analog fm transmitter exc300gx firmware, analog fm transmitter exc1600gx firmware, analog fm transmitter exc2000gx firmware, analog fm transmitter exc1000gx firmware, analog fm transmitter exc3000gx firmware, analog fm transmitter exc30gt firmware, analog fm transmitter exc300gt firmware, analog fm transmitter exc100gt firmware, analog fm transmitter exc5000gt firmware, analog fm transmitter exc1000gt firmware
Weakness
CWE-284, CWE-307
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.