The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts without proper identification or authorization. This vulnerability arises from a lack of proper cookie verification and affects all instances of SNMP Web Pro 1.1 without HTTP Digest authentication enabled, regardless of the password used for the web interface.
References
Link | Resource |
---|---|
https://gist.github.com/pedromonteirobb/a0584095b46141702c8cae0f3f1b6759 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-07-12 21:15
Updated : 2023-07-25 18:12
NVD link : CVE-2023-33274
Mitre link : CVE-2023-33274
CVE.ORG link : CVE-2023-33274
JSON object : View
Products Affected
voltronicpower
- snmp_web_pro
CWE
CWE-287
Improper Authentication