CVE-2023-46664













Sielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypass authorization and access resources behind protected pages.







ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
icscertCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 3%
VendorProductVersion
sielcopolyeco500_firmware
1.7.0
sielcopolyeco500_firmware
10.16
sielcopolyeco300_firmware
2.0.0
sielcopolyeco300_firmware
2.0.2
sielcopolyeco300_firmware
10.19
sielcopolyeco1000_firmware
1.9.3
sielcopolyeco1000_firmware
1.9.4
sielcopolyeco1000_firmware
2.0.6
sielcopolyeco1000_firmware
10.19
𝑥
= Vulnerable software versions