HIGH🇵🇱 Wersja polska

CVE-2023-39446

CVSS 8.9v3.1pub. 2023-09-18upd. 2024-11-21

Thanks to the weaknesses that the web application has at the user management level, an attacker could obtain the information from the headers that is necessary to create specially designed URLs and originate malicious actions when a legitimate user is logged into the web application.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H
  • Socomec Modulys Gp

    HW
    Socomec
    all versions
  • Socomec Modulys Gp Firmware

    OS
    Socomec
    01.12.10
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-41084CRITICAL10.0PL ✓same product

Błędne zarządzanie sesją w Socomec Modulys GP umożliwia kradzież cookie

CVE-2023-39452HIGH7.5same product

The web application that owns the device clearly stores the credentials within the user managem...

CVE-2023-40221HIGH8.8same product

The absence of filters when loading some sections in the web application of the vulnerable device...

CVE-2023-41965HIGH7.5same product

Sending some requests in the web application of the vulnerable device allows information to be obtained due to...

CVE-2023-38255MEDIUM6.5same product

A potential attacker with or without (cookie theft) access to the device would be able to inc...