CVE-2023-46663
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD
Description
Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protected pages. The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests.
Affected (9)
Products: Sielco: Polyeco500 Firmware, Polyeco300 Firmware, Polyeco1000 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.7.0 |
| Running on/with | Platform Versions |
|---|---|
Sielco Polyeco500 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.19 |
| Running on/with | Platform Versions |
|---|---|
Sielco Polyeco300 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.9.3 |
| Running on/with | Platform Versions |
|---|---|
Sielco Polyeco1000 | All versions |
References (2)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.