ZeroHour

CVE-2023-45228

CVSS 3.1
6.5 medium
EPSS
<1%p29
Published
()
Modified
Description

The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with modified parameters.

Vendors
sielco
Products
analog fm transmitter exc5000gx firmware, analog fm transmitter exc120gx firmware, analog fm transmitter exc300gx firmware, analog fm transmitter exc1600gx firmware, analog fm transmitter exc2000gx firmware, analog fm transmitter exc1000gx firmware, analog fm transmitter exc3000gx firmware, analog fm transmitter exc30gt firmware, analog fm transmitter exc300gt firmware, analog fm transmitter exc100gt firmware, analog fm transmitter exc5000gt firmware, analog fm transmitter exc1000gt firmware
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.