← Back

CVE-2023-46663

nvd nist
Published: Oct 26, 2023Modified: Nov 21, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD

Description

Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protected pages. The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests.

Affected (9)

3 products
Polyeco500 Firmware
Polyeco300 Firmware
Polyeco1000 Firmware
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Sielco
Version 1.7.0
Version 10.16
Running on/withPlatform Versions
Sielco
Polyeco500
All versions
Configuration B
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Sielco
Version 10.19
Version 2.0.0
Version 2.0.2
Running on/withPlatform Versions
Sielco
Polyeco300
All versions
Configuration C
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Sielco
Version 1.9.3
Version 1.9.4
Version 10.19
Version 2.0.6
Running on/withPlatform Versions
Sielco
Polyeco1000
All versions

References (2)

Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.