Vulnerability Description
Improper Authentication vulnerability in the cookie parameter of ZIV AUTOMATION 4CCT-EA6-334126BF allows a local attacker to perform modifications in several parameters of the affected device as an authenticated user.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zivautomation | 4Cct-Ea6-334126Bf Firmware | 3.23.77.8.33251 |
| Zivautomation | 4Cct-Ea6-334126Bf | - |
Related Weaknesses (CWE)
References
- https://www.incibe-cert.es/en/early-warning/ics-advisories/4cct-vulnerable-improThird Party Advisory
- https://www.incibe-cert.es/en/early-warning/ics-advisories/4cct-vulnerable-improThird Party Advisory
FAQ
What is CVE-2021-25910?
CVE-2021-25910 is a vulnerability with a CVSS score of 8.0 (HIGH). Improper Authentication vulnerability in the cookie parameter of ZIV AUTOMATION 4CCT-EA6-334126BF allows a local attacker to perform modifications in several parameters of the affected device as an au...
How severe is CVE-2021-25910?
CVE-2021-25910 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25910?
Check the references section above for vendor advisories and patch information. Affected products include: Zivautomation 4Cct-Ea6-334126Bf Firmware, Zivautomation 4Cct-Ea6-334126Bf.