PT-2023-15403 · Ekorrci+1 · Ekorrci+1
CVE-2022-47560
·
Publicado
2023-09-20
·
Atualizado
2024-08-03
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ekorCCP (affected versions not specified)
ekorRCI (affected versions not specified)
Description
The lack of web request control on devices allows a potential attacker to create custom requests to execute malicious actions when a user is logged in.
Recommendations
For ekorCCP, consider restricting access to the device when a user is logged in until a fix is available.
For ekorRCI, consider restricting access to the device when a user is logged in until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this issue.
Correção
Cleartext Transmission of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ekorccp
Ekorrci