Electrolink transmitters are vulnerable to an authentication bypass
vulnerability affecting the login cookie. An attacker can set an
arbitrary value except 'NO' to the login cookie and have full system
access.
References
Configurations
No configuration.
History
21 Nov 2024, 09:30
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.cisa.gov/news-events/ics-advisories/icsa-24-107-02 - |
28 May 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
Summary | (en) Electrolink transmitters are vulnerable to an authentication bypass vulnerability affecting the login cookie. An attacker can set an arbitrary value except 'NO' to the login cookie and have full system access. |
18 Apr 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-18 22:15
Updated : 2024-11-21 09:30
NVD link : CVE-2024-3741
Mitre link : CVE-2024-3741
CVE.ORG link : CVE-2024-3741
JSON object : View
Products Affected
No product.
CWE
CWE-302
Authentication Bypass by Assumed-Immutable Data