CVE-2023-39446
Summary
| CVE | CVE-2023-39446 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-18 21:15:00 UTC |
| Updated | 2023-11-07 04:17:00 UTC |
| Description | ** UNSUPPPORTED WHEN ASSIGNED ** Thanks to the weaknesses that the web application has at the user management level, an attacker could obtain the information from the headers that is necessary to create specially designed URLs and originate malicious actions when a legitimate user is logged into the web application. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Socomec | Modulys Gp | - | All | All | All |
| Operating System | Socomec | Modulys Gp Firmware | 01.12.10 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Socomec MOD3GP-SY-120K | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.