PT-2024-6298 · Unknown · Forklift Controller

Andrew Block

·

Published

2024-09-06

·

Updated

2024-09-09

·

CVE-2024-8509

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Forklift Controller (affected versions not specified)
Description A vulnerability was found in Forklift Controller due to insufficient authorization procedure. The issue arises because there is no verification against the authorization header except to ensure it uses bearer authentication. Without an Authorization header and some form of a Bearer token, a 401 error occurs. The presence of a token value provides a 200 response with the requested information. This could allow a remote attacker to disclose protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07247
CVE-2024-8509

Affected Products

Forklift Controller