On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker could use this vulnerability to spam the logged-in user with false events.
References
Link | Resource |
---|---|
https://www.trellix.com/en-us/about/newsroom/stories/research/industrial-and-manufacturing-cves.html | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: trellix
Published: 2023-06-07T06:42:31.345Z
Updated: 2023-06-07T06:42:31.345Z
Reserved: 2023-04-19T15:35:09.146Z
Link: CVE-2023-2187
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-06-07T07:15:08.740
Modified: 2023-06-16T18:06:19.557
Link: CVE-2023-2187
JSON object: View
Redhat Information
No data.