ZeroHour

CVE-2023-45317

CVSS 3.1
8.8 high
EPSS
<1%p15
Published
()
Modified
Description

The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

Vendors
sielco
Products
analog fm transmitter exc5000gx firmware, analog fm transmitter exc120gx firmware, analog fm transmitter exc300gx firmware, analog fm transmitter exc1600gx firmware, analog fm transmitter exc2000gx firmware, analog fm transmitter exc1000gx firmware, analog fm transmitter exc3000gx firmware, analog fm transmitter exc30gt firmware, analog fm transmitter exc300gt firmware, analog fm transmitter exc100gt firmware, analog fm transmitter exc5000gt firmware, analog fm transmitter exc1000gt firmware
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.