CVE-2023-28718
Summary
| CVE | CVE-2023-28718 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-28 21:15:00 UTC |
| Updated | 2023-11-07 04:10:00 UTC |
| Description | Osprey Pump Controller version 1.01 allows users to perform certain actions via HTTP requests without performing any checks to verify the requests. This may allow an attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Propumpservice | Osprey Pump Controller | - | All | All | All |
| Operating System | Propumpservice | Osprey Pump Controller Firmware | 1.01 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ProPump and Controls Osprey Pump Controller | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.