Walchem Intuition 9 firmware versions prior to v4.21 are missing authentication for some of the API routes of the management web server. This could allow an attacker to download and export sensitive data.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-229-04 Third Party Advisory US Government Resource
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2023-08-23T21:21:07.642Z

Updated: 2023-08-23T21:21:07.642Z

Reserved: 2023-07-18T21:44:31.730Z


Link: CVE-2023-38422

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-08-23T22:15:08.693

Modified: 2023-09-05T19:41:08.010


Link: CVE-2023-38422

JSON object: View

cve-icon Redhat Information

No data.

CWE