MEDIUM · 6.5

CVE-2023-45228

The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with mo...

Vulnerability Description

The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with modified parameters.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
SielcoAnalog Fm Transmitter Exc5000Gx Firmware-
SielcoAnalog Fm Transmitter Exc5000Gx2.12
SielcoAnalog Fm Transmitter Exc120Gx Firmware-
SielcoAnalog Fm Transmitter Exc120Gx2.12
SielcoAnalog Fm Transmitter Exc300Gx Firmware-
SielcoAnalog Fm Transmitter Exc300Gx2.11
SielcoAnalog Fm Transmitter Exc1600Gx Firmware-
SielcoAnalog Fm Transmitter Exc1600Gx2.10
SielcoAnalog Fm Transmitter Exc2000Gx Firmware-
SielcoAnalog Fm Transmitter Exc2000Gx2.10
SielcoAnalog Fm Transmitter Exc1000Gx Firmware-
SielcoAnalog Fm Transmitter Exc1000Gx2.08
SielcoAnalog Fm Transmitter Exc3000Gx Firmware-
SielcoAnalog Fm Transmitter Exc3000Gx2.07
SielcoAnalog Fm Transmitter Exc30Gt Firmware-
SielcoAnalog Fm Transmitter Exc30Gt1.7.7
SielcoAnalog Fm Transmitter Exc300Gt Firmware-
SielcoAnalog Fm Transmitter Exc300Gt1.7.4
SielcoAnalog Fm Transmitter Exc100Gt Firmware-
SielcoAnalog Fm Transmitter Exc100Gt1.7.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-45228?

CVE-2023-45228 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with mo...

How severe is CVE-2023-45228?

CVE-2023-45228 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-45228?

Check the references section above for vendor advisories and patch information. Affected products include: Sielco Analog Fm Transmitter Exc5000Gx Firmware, Sielco Analog Fm Transmitter Exc5000Gx, Sielco Analog Fm Transmitter Exc120Gx Firmware, Sielco Analog Fm Transmitter Exc120Gx, Sielco Analog Fm Transmitter Exc300Gx Firmware.