CVE-2023-41966
26.10.2023, 17:15
The application suffers from a privilege escalation vulnerability. A user with read permissions can elevate privileges by sending a HTTP POST to set a parameter.Enginsight
Vendor | Product | Version |
---|---|---|
sielco | analog_fm_transmitter_exc5000gx_firmware | - |
sielco | analog_fm_transmitter_exc120gx_firmware | - |
sielco | analog_fm_transmitter_exc300gx_firmware | - |
sielco | analog_fm_transmitter_exc1600gx_firmware | - |
sielco | analog_fm_transmitter_exc2000gx_firmware | - |
sielco | analog_fm_transmitter_exc1600gx_firmware | - |
sielco | analog_fm_transmitter_exc1000gx_firmware | - |
sielco | analog_fm_transmitter_exc3000gx_firmware | - |
sielco | analog_fm_transmitter_exc5000gx_firmware | - |
sielco | analog_fm_transmitter_exc30gt_firmware | - |
sielco | analog_fm_transmitter_exc300gt_firmware | - |
sielco | analog_fm_transmitter_exc100gt_firmware | - |
sielco | analog_fm_transmitter_exc5000gt_firmware | - |
sielco | analog_fm_transmitter_exc1000gt_firmware | - |
sielco | analog_fm_transmitter_exc120gt_firmware | - |
sielco | radio_link_rtx19_firmware | - |
sielco | radio_link_rtx19_firmware | - |
sielco | radio_link_exc19_firmware | - |
sielco | radio_link_rtx19_firmware | - |
sielco | radio_link_rtx19_firmware | - |
sielco | radio_link_exc19_firmware | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-267 - Privilege Defined With Unsafe ActionsA particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.
- CWE-269 - Improper Privilege ManagementThe software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.