CRITICAL · 9.8

CVE-2023-42769

The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitte...

Vulnerability Description

The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SielcoAnalog Fm Transmitter Exc5000Gx Firmware-
SielcoAnalog Fm Transmitter Exc5000Gx2.12
SielcoAnalog Fm Transmitter Exc120Gx Firmware-
SielcoAnalog Fm Transmitter Exc120Gx2.12
SielcoAnalog Fm Transmitter Exc300Gx Firmware-
SielcoAnalog Fm Transmitter Exc300Gx2.11
SielcoAnalog Fm Transmitter Exc1600Gx Firmware-
SielcoAnalog Fm Transmitter Exc1600Gx2.10
SielcoAnalog Fm Transmitter Exc2000Gx Firmware-
SielcoAnalog Fm Transmitter Exc2000Gx2.10
SielcoAnalog Fm Transmitter Exc1000Gx Firmware-
SielcoAnalog Fm Transmitter Exc1000Gx2.08
SielcoAnalog Fm Transmitter Exc3000Gx Firmware-
SielcoAnalog Fm Transmitter Exc3000Gx2.07
SielcoAnalog Fm Transmitter Exc30Gt Firmware-
SielcoAnalog Fm Transmitter Exc30Gt1.7.7
SielcoAnalog Fm Transmitter Exc300Gt Firmware-
SielcoAnalog Fm Transmitter Exc300Gt1.7.4
SielcoAnalog Fm Transmitter Exc100Gt Firmware-
SielcoAnalog Fm Transmitter Exc100Gt1.7.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-42769?

CVE-2023-42769 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitte...

How severe is CVE-2023-42769?

CVE-2023-42769 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2023-42769?

Check the references section above for vendor advisories and patch information. Affected products include: Sielco Analog Fm Transmitter Exc5000Gx Firmware, Sielco Analog Fm Transmitter Exc5000Gx, Sielco Analog Fm Transmitter Exc120Gx Firmware, Sielco Analog Fm Transmitter Exc120Gx, Sielco Analog Fm Transmitter Exc300Gx Firmware.