PT-2023-6658 · Ls Electric · Ls Electric Xbc-Dn32U

Heea Go

+4

·

Publicado

2023-02-15

·

Atualizado

2023-02-24

·

CVE-2023-22804

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LS ELECTRIC XBC-DN32U version 01.80
Description The issue is related to the absence of authentication for a critical function in the programmable logic controller's software. This could allow a remote attacker to elevate their privileges and gain control of the device by creating an account with elevated privileges.
Recommendations For LS ELECTRIC XBC-DN32U version 01.80, consider implementing authentication mechanisms to restrict access to critical functions, such as user creation on the PLC, until a patch is available. As a temporary workaround, restrict access to the device to minimize the risk of exploitation.

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07428
CVE-2023-22804

Produtos afetados

Ls Electric Xbc-Dn32U