The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts without proper identification or authorization. This vulnerability arises from a lack of proper cookie verification and affects all instances of SNMP Web Pro 1.1 without HTTP Digest authentication enabled, regardless of the password used for the web interface.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-07-12T00:00:00

Updated: 2023-07-12T00:00:00

Reserved: 2023-05-22T00:00:00


Link: CVE-2023-33274

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-07-12T21:15:09.097

Modified: 2023-07-25T18:12:32.557


Link: CVE-2023-33274

JSON object: View

cve-icon Redhat Information

No data.

CWE