PT-2023-6585 · Sielco · Sielco Polyeco1000

Published

2023-10-26

·

Updated

2023-11-06

·

CVE-2023-5754

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sielco PolyEco1000 (affected versions not specified)
Description The issue is related to insufficient restriction of authentication attempts and the use of a weak set of default administrative credentials in the Sielco PolyEco1000 digital fm-transmitter software. This weakness can be exploited by a remote attacker to gain full control of the system through remote password attacks.
Recommendations As a temporary workaround, consider changing the default administrative credentials to stronger ones until a patch is available. Restrict access to the system to minimize the risk of exploitation. Avoid using default or easily guessable credentials in the affected system until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

BDU:2023-07350
CVE-2023-5754

Affected Products

Sielco Polyeco1000