PT-2021-20344 · Circutor · Circutor Sge-Plc1000

Aarón Flecha Menéndez

·

Published

2021-06-09

·

Updated

2023-11-23

·

CVE-2021-33842

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Circutor SGE-PLC1000 version 0.9.2b
Description: The issue allows an attacker to perform operations as an authenticated user due to an improper authentication vulnerability in the cookie parameter. To exploit this, the attacker must be within the network where the affected device is located.
Recommendations: For Circutor SGE-PLC1000 version 0.9.2b, as a temporary workaround, consider restricting access to the device to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2021-33842

Affected Products

Circutor Sge-Plc1000