Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-39457

Опубликовано: 03 мая 2024
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability.

The specific flaw exists due to the lack of user authentication. The issue results from missing authentication in the default system configuration. An attacker can leverage this vulnerability to execute arbitrary code in the context of root. Was ZDI-CAN-20501.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:trianglemicroworks:scada_data_gateway:5.1.3.20324:*:*:*:*:*:*:*

EPSS

Процентиль: 59%
0.00378
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.8
github
почти 2 года назад

Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. The specific flaw exists due to the lack of user authentication. The issue results from missing authentication in the default system configuration. An attacker can leverage this vulnerability to execute arbitrary code in the context of root. Was ZDI-CAN-20501.

CVSS3: 9.8
fstec
больше 2 лет назад

Уязвимость SCADA-системы SCADA Data Gateway (SDG), связанная с недостатками процедуры аутентификации, позволяющая нарушителю обойти ограничения безопасности и получить несанкционированный доступ к системе

EPSS

Процентиль: 59%
0.00378
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306