Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-2187


On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker could use this vulnerability to spam the logged-in user with false events.


Published

2023-06-07T07:15:08.740

Last Modified

2024-11-21T07:58:06.437

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-306
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application trianglemicroworks scada_data_gateway ≤ 5.01.03 Yes

References