PT-2021-20344 · Circutor · Circutor Sge-Plc1000
Aarón Flecha Menéndez
·
Published
2021-06-09
·
Updated
2023-11-23
·
CVE-2021-33842
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Circutor SGE-PLC1000 version 0.9.2b
Description:
The issue allows an attacker to perform operations as an authenticated user due to an improper authentication vulnerability in the
cookie parameter. To exploit this, the attacker must be within the network where the affected device is located.Recommendations:
For Circutor SGE-PLC1000 version 0.9.2b, as a temporary workaround, consider restricting access to the device to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Circutor Sge-Plc1000