Vulnerability Description
Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware version 0.9.2b allows an attacker to perform operations as an authenticated user. In order to exploit this vulnerability, the attacker must be within the network where the device affected is located.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Circutor | Sge-Plc1000 Firmware | 0.9.2b |
| Circutor | Sge-Plc1000 | - |
Related Weaknesses (CWE)
References
- https://www.incibe.es/en/incibe-cert/notices/aviso-sci/circutor-sge-plc1000-impr
- https://www.incibe.es/en/incibe-cert/notices/aviso-sci/circutor-sge-plc1000-impr
FAQ
What is CVE-2021-33842?
CVE-2021-33842 is a vulnerability with a CVSS score of 8.8 (HIGH). Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware version 0.9.2b allows an attacker to perform operations as an authenticated user. In order to exploit thi...
How severe is CVE-2021-33842?
CVE-2021-33842 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-33842?
Check the references section above for vendor advisories and patch information. Affected products include: Circutor Sge-Plc1000 Firmware, Circutor Sge-Plc1000.