CVE-2023-46663
Summary
| CVE | CVE-2023-46663 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-26 21:15:00 UTC |
| Updated | 2023-11-07 16:13:00 UTC |
| Description | Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protected pages. The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Sielco | Polyeco1000 | - | All | All | All |
| Operating System | Sielco | Polyeco1000 Firmware | 1.9.3 | All | All | All |
| Operating System | Sielco | Polyeco1000 Firmware | 1.9.4 | All | All | All |
| Operating System | Sielco | Polyeco1000 Firmware | 10.19 | All | All | All |
| Operating System | Sielco | Polyeco1000 Firmware | 2.0.6 | All | All | All |
| Hardware | Sielco | Polyeco300 | - | All | All | All |
| Operating System | Sielco | Polyeco300 Firmware | 10.19 | All | All | All |
| Operating System | Sielco | Polyeco300 Firmware | 2.0.0 | All | All | All |
| Operating System | Sielco | Polyeco300 Firmware | 2.0.2 | All | All | All |
| Hardware | Sielco | Polyeco500 | - | All | All | All |
| Operating System | Sielco | Polyeco500 Firmware | 1.7.0 | All | All | All |
| Operating System | Sielco | Polyeco500 Firmware | 10.16 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Sielco PolyEco FM Transmitter | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.