Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware version 0.9.2b allows an attacker to perform operations as an authenticated user. In order to exploit this vulnerability, the attacker must be within the network where the device affected is located.
References
Link | Resource |
---|---|
https://www.incibe-cert.es/en/early-warning/ics-advisories/circutor-sge-plc1000-improper-authentication | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2021-06-09 05:15
Updated : 2022-10-25 16:40
NVD link : CVE-2021-33842
Mitre link : CVE-2021-33842
JSON object : View
CWE
CWE-565
Reliance on Cookies without Validation and Integrity Checking
Products Affected
circutor
- sge-plc1000
- sge-plc1000_firmware