Vulnerability Description
Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protected pages. The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sielco | Polyeco500 Firmware | 1.7.0 |
| Sielco | Polyeco500 | - |
| Sielco | Polyeco300 Firmware | 2.0.0 |
| Sielco | Polyeco300 | - |
| Sielco | Polyeco1000 Firmware | 1.9.3 |
| Sielco | Polyeco1000 | - |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-299-07Third Party AdvisoryUS Government Resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-299-07Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2023-46663?
CVE-2023-46663 is a vulnerability with a CVSS score of 7.5 (HIGH). Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protected pages. The application interface allows users to perform certain actions via H...
How severe is CVE-2023-46663?
CVE-2023-46663 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-46663?
Check the references section above for vendor advisories and patch information. Affected products include: Sielco Polyeco500 Firmware, Sielco Polyeco500, Sielco Polyeco300 Firmware, Sielco Polyeco300, Sielco Polyeco1000 Firmware.