PT-2024-13145 · Aten · Aten Pe6208

Published

2024-05-28

·

Updated

2024-08-23

·

CVE-2023-43847

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Aten PE6208 versions 2.3.228 through 2.4.232
Description The issue is related to incorrect access control in the outlet control function of the web interface, allowing remote authenticated users to control all outlets as if they were the administrator. This can be achieved via HTTP POST requests.
Recommendations For versions 2.3.228 through 2.4.232, consider restricting access to the outlet control function until a patch is available. As a temporary workaround, restrict the use of HTTP POST requests to the vulnerable outlet control function. Avoid using the outlet control function in the web interface until the issue is resolved.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2023-43847

Affected Products

Aten Pe6208