Lucene search

K
cveMitreCVE-2023-33274
HistoryJul 12, 2023 - 9:15 p.m.

CVE-2023-33274

2023-07-1221:15:09
CWE-287
mitre
web.nvd.nist.gov
29
cve-2023-33274
powershield
snmp web pro
authentication mechanism
vulnerability
unauthenticated access
cgi scripts
http digest authentication

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.004

Percentile

73.0%

The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts without proper identification or authorization. This vulnerability arises from a lack of proper cookie verification and affects all instances of SNMP Web Pro 1.1 without HTTP Digest authentication enabled, regardless of the password used for the web interface.

Affected configurations

Nvd
Node
voltronicpowersnmp_web_proMatch1.1
VendorProductVersionCPE
voltronicpowersnmp_web_pro1.1cpe:2.3:a:voltronicpower:snmp_web_pro:1.1:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.004

Percentile

73.0%

Related for CVE-2023-33274