Vulnerability Description
Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, thereby gaining unauthorized access to the system. A threat actor could exploit this vulnerability to create a user account without providing valid credentials. A threat actor who successfully exploits this vulnerability could gain access to the pump controller and cause disruption in operation, modify data, or shut down the controller.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Propumpservice | Osprey Pump Controller Firmware | 1.01 |
| Propumpservice | Osprey Pump Controller | - |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-06Third Party AdvisoryUS Government Resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-06Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2023-28398?
CVE-2023-28398 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, thereby gaining unauthorized access to the system. A threat actor could exploit ...
How severe is CVE-2023-28398?
CVE-2023-28398 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-28398?
Check the references section above for vendor advisories and patch information. Affected products include: Propumpservice Osprey Pump Controller Firmware, Propumpservice Osprey Pump Controller.