Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware version 0.9.2b allows an attacker to perform operations as an authenticated user. In order to exploit this vulnerability, the attacker must be within the network where the device affected is located.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 06:09
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/circutor-sge-plc1000-improper-authentication - |
09 Nov 2023, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2021-06-09 12:15
Updated : 2024-11-21 06:09
NVD link : CVE-2021-33842
Mitre link : CVE-2021-33842
CVE.ORG link : CVE-2021-33842
JSON object : View
Products Affected
circutor
- sge-plc1000_firmware
- sge-plc1000
CWE
CWE-565
Reliance on Cookies without Validation and Integrity Checking