PT-2023-7925 · Eurotel · Eurotel Etl3100

·

CVE-2023-6929

·

Publicado

2023-04-29

·

Atualizado

2023-12-29

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EuroTel ETL3100 versions v01c01 and v01x37
Description The issue is related to insecure direct object references, which occur when the application provides direct access to objects based on user-supplied input. This allows attackers to bypass authorization, access hidden resources on the system, and execute privileged functionalities. The vulnerability can be exploited by using a user-controlled key to bypass security restrictions, resulting in unauthorized access to protected information and elevated privileges.
Recommendations For EuroTel ETL3100 versions v01c01 and v01x37, consider restricting access to sensitive resources and functionalities to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the application's ability to provide direct access to objects based on user-supplied input.

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-09003
CVE-2023-6929

Produtos afetados

Eurotel Etl3100