Lucene search

K
nvd[email protected]NVD:CVE-2023-33274
HistoryJul 12, 2023 - 9:15 p.m.

CVE-2023-33274

2023-07-1221:15:09
CWE-287
web.nvd.nist.gov
3
powershield
snmp web pro
authentication
vulnerability
cgi scripts
http digest

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.004

Percentile

73.0%

The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts without proper identification or authorization. This vulnerability arises from a lack of proper cookie verification and affects all instances of SNMP Web Pro 1.1 without HTTP Digest authentication enabled, regardless of the password used for the web interface.

Affected configurations

Nvd
Node
voltronicpowersnmp_web_proMatch1.1
VendorProductVersionCPE
voltronicpowersnmp_web_pro1.1cpe:2.3:a:voltronicpower:snmp_web_pro:1.1:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.004

Percentile

73.0%

Related for NVD:CVE-2023-33274