Vulnerabilities > Sielco > Analog FM Transmitter Exc30Gt Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-10-26 CVE-2023-41966 Improper Privilege Management vulnerability in Sielco products
The application suffers from a privilege escalation vulnerability.
network
low complexity
sielco CWE-269
8.8
2023-10-26 CVE-2023-42769 Improper Restriction of Excessive Authentication Attempts vulnerability in Sielco products
The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.
network
low complexity
sielco CWE-307
critical
9.8
2023-10-26 CVE-2023-45228 Unspecified vulnerability in Sielco products
The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with modified parameters.
network
low complexity
sielco
6.5
2023-10-26 CVE-2023-45317 Cross-Site Request Forgery (CSRF) vulnerability in Sielco products
The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests.
network
low complexity
sielco CWE-352
8.8