Vulnerability Description
The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with modified parameters.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sielco | Analog Fm Transmitter Exc5000Gx Firmware | - |
| Sielco | Analog Fm Transmitter Exc5000Gx | 2.12 |
| Sielco | Analog Fm Transmitter Exc120Gx Firmware | - |
| Sielco | Analog Fm Transmitter Exc120Gx | 2.12 |
| Sielco | Analog Fm Transmitter Exc300Gx Firmware | - |
| Sielco | Analog Fm Transmitter Exc300Gx | 2.11 |
| Sielco | Analog Fm Transmitter Exc1600Gx Firmware | - |
| Sielco | Analog Fm Transmitter Exc1600Gx | 2.10 |
| Sielco | Analog Fm Transmitter Exc2000Gx Firmware | - |
| Sielco | Analog Fm Transmitter Exc2000Gx | 2.10 |
| Sielco | Analog Fm Transmitter Exc1000Gx Firmware | - |
| Sielco | Analog Fm Transmitter Exc1000Gx | 2.08 |
| Sielco | Analog Fm Transmitter Exc3000Gx Firmware | - |
| Sielco | Analog Fm Transmitter Exc3000Gx | 2.07 |
| Sielco | Analog Fm Transmitter Exc30Gt Firmware | - |
| Sielco | Analog Fm Transmitter Exc30Gt | 1.7.7 |
| Sielco | Analog Fm Transmitter Exc300Gt Firmware | - |
| Sielco | Analog Fm Transmitter Exc300Gt | 1.7.4 |
| Sielco | Analog Fm Transmitter Exc100Gt Firmware | - |
| Sielco | Analog Fm Transmitter Exc100Gt | 1.7.4 |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-299-08Third Party AdvisoryUS Government Resource
- https://www.sielco.org/en/contactsProduct
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-299-08Third Party AdvisoryUS Government Resource
- https://www.sielco.org/en/contactsProduct
FAQ
What is CVE-2023-45228?
CVE-2023-45228 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with mo...
How severe is CVE-2023-45228?
CVE-2023-45228 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-45228?
Check the references section above for vendor advisories and patch information. Affected products include: Sielco Analog Fm Transmitter Exc5000Gx Firmware, Sielco Analog Fm Transmitter Exc5000Gx, Sielco Analog Fm Transmitter Exc120Gx Firmware, Sielco Analog Fm Transmitter Exc120Gx, Sielco Analog Fm Transmitter Exc300Gx Firmware.