Vulnerability Description
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command. This could allow an attacker to delete arbitrary files.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ls-Electric | Xbc-Dn32U Firmware | 01.80 |
| Ls-Electric | Xbc-Dn32U | - |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-23-040-02Broken LinkThird Party AdvisoryUS Government Resource
- https://www.cisa.gov/uscert/ics/advisories/icsa-23-040-02Broken LinkThird Party AdvisoryUS Government Resource
FAQ
What is CVE-2023-0102?
CVE-2023-0102 is a vulnerability with a CVSS score of 9.1 (CRITICAL). LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command. This could allow an attacker to delete arbitrary files.
How severe is CVE-2023-0102?
CVE-2023-0102 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-0102?
Check the references section above for vendor advisories and patch information. Affected products include: Ls-Electric Xbc-Dn32U Firmware, Ls-Electric Xbc-Dn32U.