Логотип exploitDog
bind:CVE-2023-2187
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-2187

Количество 3

Количество 3

nvd логотип

CVE-2023-2187

больше 2 лет назад

On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker could use this vulnerability to spam the logged-in user with false events.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-qp2h-3p7w-4v89

больше 2 лет назад

On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker could use this vulnerability to spam the logged-in user with false events.

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2023-03107

почти 3 года назад

Уязвимость компонента WebMonitor SCADA-системы SCADA Data Gateway (SDG), позволяющая нарушителю обойти процедуру аутентификации и повысить свои привилегии путем

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-2187

On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker could use this vulnerability to spam the logged-in user with false events.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-qp2h-3p7w-4v89

On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker could use this vulnerability to spam the logged-in user with false events.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2023-03107

Уязвимость компонента WebMonitor SCADA-системы SCADA Data Gateway (SDG), позволяющая нарушителю обойти процедуру аутентификации и повысить свои привилегии путем

CVSS3: 5.3
0%
Низкий
почти 3 года назад

Уязвимостей на страницу