PT-2023-3720 · Elenos · Elenos Etg150 Fm Transmitter
Eslam Kamal
+1
·
Published
2023-06-23
·
Updated
2024-12-05
·
CVE-2023-34672
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Elenos ETG150 FM transmitter version 3.12
Description
The issue is related to improper access control, which can be exploited to add a high-privilege user by leveraging the user's role within the admin profile. This can potentially be done over the public Internet. The vulnerability is associated with software deficiencies in access control.
Recommendations
For version 3.12, consider restricting access to the admin profile to minimize the risk of exploitation until a patch is available. As a temporary workaround, review and limit user roles within the admin profile to prevent unauthorized privilege escalation.
Exploit
Fix
Improper Access Control
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Elenos Etg150 Fm Transmitter