PT-2023-7363 · Hgiga · Hgiga Powerstation

Chiu Tsungshu

+1

·

Published

2023-01-31

·

Updated

2023-06-05

·

CVE-2023-24838

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HGiga PowerStation (affected versions not specified)
Description The issue is related to a lack of authentication for a critical function due to insufficient protection of service data, which can allow a remote attacker to gain unauthorized access to protected information, execute arbitrary code, or cause a denial of service. An unauthenticated remote attacker can exploit this to obtain the administrator's credential, which can then be used to login to PowerStation or Secure Shell to achieve remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2023-08395
CVE-2023-24838

Affected Products

Hgiga Powerstation