« Volver al listado

CVE-2023-46664

Estado: ModificadaCrítica (9.1)—

Sielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypass authorization and access resources behind protected pages.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-46664",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-46664",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-16T21:20:36.232976Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ics-cert@hq.dhs.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "Sielco ",
          "product": "PolyEco1000",
          "versions": [
            {
              "status": "affected",
              "version": "CPU:2.0.6 FPGA:10.19"
            },
            {
              "status": "affected",
              "version": "CPU:1.9.4 FPGA:10.19"
            },
            {
              "status": "affected",
              "version": "CPU:1.9.3 FPGA:10.19"
            },
            {
              "status": "affected",
              "version": "CPU:1.7.0 FPGA:10.16"
            },
            {
              "status": "affected",
              "version": "CPU:2.0.2 FPGA:10.19"
            },
            {
              "status": "affected",
              "version": "CPU:2.0.0 FPGA:10.19"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-10-26T21:15:07.967",
  "references": [
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-299-07",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-299-07",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ics-cert@hq.dhs.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\n\n\n\n\n\n\n\n\n\n\n\n\nSielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypass authorization and access resources behind protected pages.\n\n\n\n\n\n\n\n"
    },
    {
      "lang": "es",
      "value": "Sielco PolyEco1000 es afectada por una vulnerabilidad de control de acceso inadecuado cuando la aplicación proporciona acceso directo a objetos basándose en la entrada proporcionada por el usuario. Como resultado de esta vulnerabilidad, los atacantes pueden eludir la autorización y acceder a recursos detrás de páginas protegidas."
    }
  ],
  "lastModified": "2026-06-17T06:31:19.390",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sielco:polyeco500_firmware:1.7.0:*:*:*:cpu:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E64F96A4-542A-486E-AC9A-3EC1E68A6D1E"
            },
            {
              "criteria": "cpe:2.3:o:sielco:polyeco500_firmware:10.16:*:*:*:fpga:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3A4049B-D0B2-4CB6-8B31-ECD3BF4FF384"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sielco:polyeco500:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D7E931F0-5608-4F24-821B-3DB29972C077"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sielco:polyeco300_firmware:2.0.0:*:*:*:cpu:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BBA5260D-A7D3-4973-8106-E8C73F50A6CE"
            },
            {
              "criteria": "cpe:2.3:o:sielco:polyeco300_firmware:2.0.2:*:*:*:cpu:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7CE9236-A970-49F0-A200-84BC3B77CECB"
            },
            {
              "criteria": "cpe:2.3:o:sielco:polyeco300_firmware:10.19:*:*:*:fpga:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D45CE1CD-FB47-4FFD-974E-B55B569A5850"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sielco:polyeco300:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "05832105-6C9E-4850-A145-F3E241058CCA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sielco:polyeco1000_firmware:1.9.3:*:*:*:cpu:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "991B1AD8-671D-4EF9-901B-0834748258F5"
            },
            {
              "criteria": "cpe:2.3:o:sielco:polyeco1000_firmware:1.9.4:*:*:*:cpu:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE961B31-1553-4457-8436-8F9662AA10CA"
            },
            {
              "criteria": "cpe:2.3:o:sielco:polyeco1000_firmware:2.0.6:*:*:*:cpu:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0BF0380D-483C-4B14-BF42-AC1E9C79D2DE"
            },
            {
              "criteria": "cpe:2.3:o:sielco:polyeco1000_firmware:10.19:*:*:*:fpga:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F0E5773E-8842-4FCB-80BD-266A237042E7"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sielco:polyeco1000:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "01DB9D87-6F35-4171-AD59-9B90386F431E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}