Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware version 0.9.2b allows an attacker to perform operations as an authenticated user. In order to exploit this vulnerability, the attacker must be within the network where the device affected is located.
References
Configurations
Configuration 1 (hide)
AND |
|
History
23 Nov 2023, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
25 Oct 2022, 23:40
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-565 |
21 Jun 2021, 20:49
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:circutor:sge-plc1000_firmware:0.9.2b:*:*:*:*:*:*:* cpe:2.3:h:circutor:sge-plc1000:-:*:*:*:*:*:*:* |
|
References | (CONFIRM) https://www.incibe-cert.es/en/early-warning/ics-advisories/circutor-sge-plc1000-improper-authentication - Third Party Advisory | |
CWE | CWE-287 | |
CVSS |
v2 : v3 : |
v2 : 7.7
v3 : 8.8 |
09 Jun 2021, 12:38
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-06-09 12:15
Updated : 2024-02-04 21:47
NVD link : CVE-2021-33842
Mitre link : CVE-2021-33842
CVE.ORG link : CVE-2021-33842
JSON object : View
Products Affected
circutor
- sge-plc1000
- sge-plc1000_firmware
CWE
CWE-565
Reliance on Cookies without Validation and Integrity Checking