CVE-2023-39446
Published on: Not Yet Published
Last Modified on: 09/21/2023 06:36:00 PM UTC
Certain versions of Modulys Gp from Socomec contain the following vulnerability:
** UNSUPPPORTED WHEN ASSIGNED ** Thanks to the weaknesses that the web application has at the user management level, an attacker could obtain the information from the headers that is necessary to create specially designed URLs and originate malicious actions when a legitimate user is logged into the web application.
- CVE-2023-39446 has been assigned by
ics-[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Socomec - MODULYS GP (MOD3GP-SY-120K) version = v01.12.10
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Socomec MOD3GP-SY-120K | CISA | www.cisa.gov text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Socomec | Modulys Gp | - | All | All | All |
Operating System | Socomec | Modulys Gp Firmware | 01.12.10 | All | All | All |
- cpe:2.3:h:socomec:modulys_gp:-:*:*:*:*:*:*:*:
- cpe:2.3:o:socomec:modulys_gp_firmware:01.12.10:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE