PT-2023-26416 · Walchem · Walchem Intuition 9

Noam Moshe

·

Published

2023-08-23

·

Updated

2023-09-05

·

CVE-2023-38422

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Walchem Intuition 9 firmware versions prior to v4.21
Description The issue is related to missing authentication for some API routes of the management web server. This could allow an attacker to download and export sensitive data.
Recommendations For Walchem Intuition 9 firmware versions prior to v4.21, update to version v4.21 or later to resolve the issue.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-38422

Affected Products

Walchem Intuition 9