PT-2024-6298 · Unknown · Forklift Controller
Andrew Block
·
Published
2024-09-06
·
Updated
2024-09-09
·
CVE-2024-8509
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Forklift Controller (affected versions not specified)
Description
A vulnerability was found in Forklift Controller due to insufficient authorization procedure. The issue arises because there is no verification against the authorization header except to ensure it uses bearer authentication. Without an Authorization header and some form of a Bearer token, a 401 error occurs. The presence of a token value provides a 200 response with the requested information. This could allow a remote attacker to disclose protected information.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forklift Controller