Known Vulnerabilities for products from Sielco
Listed below are 11 of the newest known vulnerabilities associated with the vendor "Sielco".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-46665 json | Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying pass... | 9.8 - CRITICAL | 2023-10-26 | 2023-11-07 |
| CVE-2023-46664 json | Sielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides direc... | 9.1 - CRITICAL | 2023-10-26 | 2023-11-07 |
| CVE-2023-46663 json | Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protected pag... | 8.1 - HIGH | 2023-10-26 | 2023-11-07 |
| CVE-2023-46662 json | Sielco PolyEco1000 is vulnerable to an information disclosure vulnerability due to improper access control enforcement. ... | 7.5 - HIGH | 2023-10-26 | 2023-11-06 |
| CVE-2023-46661 json | Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests. | 9.8 - CRITICAL | 2023-10-26 | 2023-11-06 |
| CVE-2023-45317 json | The application interface allows users to perform certain actions via HTTP requests without performing any validity checks ... | 8.8 - HIGH | 2023-10-26 | 2023-11-07 |
| CVE-2023-45228 json | The application suffers from improper access control when editing users. A user with read permissions can manipulate users... | 6.5 - MEDIUM | 2023-10-26 | 2023-11-07 |
| CVE-2023-42769 json | The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to ob... | 9.8 - CRITICAL | 2023-10-26 | 2023-11-07 |
| CVE-2023-41966 json | The application suffers from a privilege escalation vulnerability. A user with read permissions can elevate privileges by... | 8.8 - HIGH | 2023-10-26 | 2023-11-07 |
| CVE-2023-5754 json | Sielco PolyEco1000 uses a weak set of default administrative credentials that can be easily guessed in remote password a... | 9.8 - CRITICAL | 2023-10-26 | 2023-11-06 |
| CVE-2023-0897 json | Sielco PolyEco1000 is vulnerable to a session hijack vulnerability due to the cookie being vulnerable to a brute force attac... | 9.8 - CRITICAL | 2023-10-26 | 2023-11-07 |