CVE-2023-42769
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
The cookie session ID is of insufficient length and can be exploited by
brute force, which may allow a remote attacker to obtain a valid
session, bypass authentication, and manipulate the transmitter.
Affected (15)
Products: Sielco: Analog Fm Transmitter Exc120gx Firmware, Analog Fm Transmitter Exc300gx Firmware, Analog Fm Transmitter Exc2000gx Firmware, Analog Fm Transmitter Exc1600gx Firmware, Analog Fm Transmitter Exc1000gx Firmware, Analog Fm Transmitter Exc3000gx Firmware, Analog Fm Transmitter Exc5000gx Firmware, Analog Fm Transmitter Exc30gt Firmware, Analog Fm Transmitter Exc300gt Firmware, Analog Fm Transmitter Exc100gt Firmware, Analog Fm Transmitter Exc5000gt Firmware, Analog Fm Transmitter Exc1000gt Firmware, Analog Fm Transmitter Exc120gt Firmware, Radio Link Rtx19 Firmware, Radio Link Exc19 Firmware
Configuration A
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc5000gx | Version 2.12 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc120gx | Version 2.12 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc300gx | Version 2.11 |
Configuration D
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc1600gx | Version 2.10 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc2000gx | Version 2.10 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc1600gx | Version 2.08 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc1000gx | Version 2.08 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc3000gx | Version 2.07 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc5000gx | Version 2.06 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc30gt | Version 1.7.7 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc300gt | Version 1.7.4 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc100gt | Version 1.7.4 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc5000gt | Version 1.7.4 |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc1000gt | Version 1.6.3 |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Analog Fm Transmitter Exc120gt | Version 1.5.4 |
Configuration P
| Running on/with | Platform Versions |
|---|---|
Sielco Radio Link Rtx19 | Version 2.06 |
Configuration Q
| Running on/with | Platform Versions |
|---|---|
Sielco Radio Link Rtx19 | Version 2.05 |
Configuration R
| Running on/with | Platform Versions |
|---|---|
Sielco Radio Link Exc19 | Version 2.00 |
Configuration S
| Running on/with | Platform Versions |
|---|---|
Sielco Radio Link Rtx19 | Version 1.60 |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Radio Link Rtx19 | Version 1.59 |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sielco Radio Link Exc19 | Version 1.55 |
Related CWEs
CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-307
Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks.
References (4)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.