CVE-2023-46664
26.10.2023, 21:15
Sielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypass authorization and access resources behind protected pages.Enginsight
Vendor | Product | Version |
---|---|---|
sielco | polyeco500_firmware | 1.7.0 |
sielco | polyeco500_firmware | 10.16 |
sielco | polyeco300_firmware | 2.0.0 |
sielco | polyeco300_firmware | 2.0.2 |
sielco | polyeco300_firmware | 10.19 |
sielco | polyeco1000_firmware | 1.9.3 |
sielco | polyeco1000_firmware | 1.9.4 |
sielco | polyeco1000_firmware | 2.0.6 |
sielco | polyeco1000_firmware | 10.19 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration