Vulnerability Description
The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts without proper identification or authorization. This vulnerability arises from a lack of proper cookie verification and affects all instances of SNMP Web Pro 1.1 without HTTP Digest authentication enabled, regardless of the password used for the web interface.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Voltronicpower | Snmp Web Pro | 1.1 |
Related Weaknesses (CWE)
References
- https://gist.github.com/pedromonteirobb/a0584095b46141702c8cae0f3f1b6759ExploitThird Party Advisory
- https://gist.github.com/pedromonteirobb/a0584095b46141702c8cae0f3f1b6759ExploitThird Party Advisory
FAQ
What is CVE-2023-33274?
CVE-2023-33274 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts without proper identif...
How severe is CVE-2023-33274?
CVE-2023-33274 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-33274?
Check the references section above for vendor advisories and patch information. Affected products include: Voltronicpower Snmp Web Pro.