Sielco
Sielco Polyeco500 Firmware: vulnerabilidades y CVE
Sielco Polyeco500 Firmware tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-46665 | Crítica (9.8) | 0.65% | — | 26 oct 2023 | Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthorized access to the affected device with administrative privileges. |
| CVE-2023-46664 | Crítica (9.1) | 0.50% | — | 26 oct 2023 | Sielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypass… |
| CVE-2023-46663 | Alta (8.1) | 0.44% | — | 26 oct 2023 | Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protected pages. The application interface allows users to perform certain actions via HTTP requests without… |
| CVE-2023-5754 | Crítica (9.8) | 0.49% | — | 26 oct 2023 | Sielco PolyEco1000 uses a weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system. |
| CVE-2023-46662 | Alta (7.5) | 0.58% | — | 26 oct 2023 | Sielco PolyEco1000 is vulnerable to an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote attacker can exploit this via a specially crafted request to gain access… |
| CVE-2023-46661 | Crítica (9.8) | 0.54% | — | 26 oct 2023 | Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests. |
| CVE-2023-0897 | Crítica (9.8) | 0.47% | — | 26 oct 2023 | Sielco PolyEco1000 is vulnerable to a session hijack vulnerability due to the cookie being vulnerable to a brute force attack, lack of SSL, and the session being visible in requests. |
Otros productos de Sielco
Polyeco1000 Firmware · 7Polyeco300 Firmware · 7Analog FM Transmitter Exc100gt Firmware · 4Analog FM Transmitter Exc120gt Firmware · 4Analog FM Transmitter Exc120gx Firmware · 4Analog FM Transmitter Exc1600gx Firmware · 4Analog FM Transmitter Exc2000gx Firmware · 4Analog FM Transmitter Exc3000gx Firmware · 4Analog FM Transmitter Exc300gt Firmware · 4Analog FM Transmitter Exc300gx Firmware · 4Analog FM Transmitter Exc30gt Firmware · 4Analog FM Transmitter Exc5000gt Firmware · 4