HIGH · 8.8

CVE-2023-45317

The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions w...

Vulnerability Description

The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SielcoAnalog Fm Transmitter Exc5000Gx Firmware-
SielcoAnalog Fm Transmitter Exc5000Gx2.12
SielcoAnalog Fm Transmitter Exc120Gx Firmware-
SielcoAnalog Fm Transmitter Exc120Gx2.12
SielcoAnalog Fm Transmitter Exc300Gx Firmware-
SielcoAnalog Fm Transmitter Exc300Gx2.11
SielcoAnalog Fm Transmitter Exc1600Gx Firmware-
SielcoAnalog Fm Transmitter Exc1600Gx2.10
SielcoAnalog Fm Transmitter Exc2000Gx Firmware-
SielcoAnalog Fm Transmitter Exc2000Gx2.10
SielcoAnalog Fm Transmitter Exc1000Gx Firmware-
SielcoAnalog Fm Transmitter Exc1000Gx2.08
SielcoAnalog Fm Transmitter Exc3000Gx Firmware-
SielcoAnalog Fm Transmitter Exc3000Gx2.07
SielcoAnalog Fm Transmitter Exc30Gt Firmware-
SielcoAnalog Fm Transmitter Exc30Gt1.7.7
SielcoAnalog Fm Transmitter Exc300Gt Firmware-
SielcoAnalog Fm Transmitter Exc300Gt1.7.4
SielcoAnalog Fm Transmitter Exc100Gt Firmware-
SielcoAnalog Fm Transmitter Exc100Gt1.7.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-45317?

CVE-2023-45317 is a vulnerability with a CVSS score of 8.8 (HIGH). The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions w...

How severe is CVE-2023-45317?

CVE-2023-45317 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-45317?

Check the references section above for vendor advisories and patch information. Affected products include: Sielco Analog Fm Transmitter Exc5000Gx Firmware, Sielco Analog Fm Transmitter Exc5000Gx, Sielco Analog Fm Transmitter Exc120Gx Firmware, Sielco Analog Fm Transmitter Exc120Gx, Sielco Analog Fm Transmitter Exc300Gx Firmware.