CVE-2024-3741

Electrolink transmitters are vulnerable to an authentication bypass vulnerability affecting the login cookie. An attacker can set an arbitrary value except 'NO' to the login cookie and have full system access.
Configurations

No configuration.

History

21 Nov 2024, 09:30

Type Values Removed Values Added
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-107-02 - () https://www.cisa.gov/news-events/ics-advisories/icsa-24-107-02 -

28 May 2024, 17:15

Type Values Removed Values Added
Summary
  • (es) Los transmisores Electrolink son afectados una vulnerabilidad de omisión de autenticación que afecta la cookie de inicio de sesión. Un atacante puede establecer un valor arbitrario excepto 'NO' para la cookie de inicio de sesión y tener acceso completo al sistema.
Summary (en) Electrolink transmitters are vulnerable to an authentication bypass vulnerability affecting the login cookie. An attacker can set an arbitrary value except 'NO' to the login cookie and have full system access. (en) Electrolink transmitters are vulnerable to an authentication bypass vulnerability affecting the login cookie. An attacker can set an arbitrary value except 'NO' to the login cookie and have full system access.

18 Apr 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-18 22:15

Updated : 2024-11-21 09:30


NVD link : CVE-2024-3741

Mitre link : CVE-2024-3741

CVE.ORG link : CVE-2024-3741


JSON object : View

Products Affected

No product.

CWE
CWE-302

Authentication Bypass by Assumed-Immutable Data