The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts without proper identification or authorization. This vulnerability arises from a lack of proper cookie verification and affects all instances of SNMP Web Pro 1.1 without HTTP Digest authentication enabled, regardless of the password used for the web interface.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-37439 | The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts without proper identification or authorization. This vulnerability arises from a lack of proper cookie verification and affects all instances of SNMP Web Pro 1.1 without HTTP Digest authentication enabled, regardless of the password used for the web interface. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 07 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-07T17:06:31.464Z
Reserved: 2023-05-22T00:00:00
Link: CVE-2023-33274
Updated: 2024-08-02T15:39:36.109Z
Status : Modified
Published: 2023-07-12T21:15:09.097
Modified: 2024-11-21T08:05:18.450
Link: CVE-2023-33274
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD