CVE-2023-41966
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
The application suffers from a privilege escalation vulnerability. A
user with read permissions can elevate privileges by sending a HTTP POST
to set a parameter.
Affected (15)
Products: Sielco: Analog Fm Transmitter Exc120gx Firmware, Analog Fm Transmitter Exc300gx Firmware, Analog Fm Transmitter Exc2000gx Firmware, Analog Fm Transmitter Exc1600gx Firmware, Analog Fm Transmitter Exc1000gx Firmware, Analog Fm Transmitter Exc3000gx Firmware, Analog Fm Transmitter Exc5000gx Firmware, Analog Fm Transmitter Exc30gt Firmware, Analog Fm Transmitter Exc300gt Firmware, Analog Fm Transmitter Exc100gt Firmware, Analog Fm Transmitter Exc5000gt Firmware, Analog Fm Transmitter Exc1000gt Firmware, Analog Fm Transmitter Exc120gt Firmware, Radio Link Rtx19 Firmware, Radio Link Exc19 Firmware
Configuration A
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc5000gx | Version 2.12 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc120gx | Version 2.12 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc300gx | Version 2.11 |
Configuration D
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc1600gx | Version 2.10 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc2000gx | Version 2.10 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc1600gx | Version 2.08 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc1000gx | Version 2.08 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc3000gx | Version 2.07 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc5000gx | Version 2.06 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc30gt | Version 1.7.7 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc300gt | Version 1.7.4 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc100gt | Version 1.7.4 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc5000gt | Version 1.7.4 |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc1000gt | Version 1.6.3 |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc120gt | Version 1.5.4 |
Configuration P
| Running on/with | Platform Versions |
|---|---|
Sielco Radio Link Rtx19 | Version 2.06 |
Configuration Q
| Running on/with | Platform Versions |
|---|---|
Sielco Radio Link Rtx19 | Version 2.05 |
Configuration R
| Running on/with | Platform Versions |
|---|---|
Sielco Radio Link Exc19 | Version 2.00 |
Configuration S
| Running on/with | Platform Versions |
|---|---|
Sielco Radio Link Rtx19 | Version 1.60 |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Radio Link Rtx19 | Version 1.59 |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Radio Link Exc19 | Version 1.55 |
Related CWEs
CWE-267
Privilege Defined With Unsafe Actions
A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.
CWE-269
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
References (4)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.