E
lectrolink transmitters are vulnerable to an authentication bypass vulnerability affecting the login cookie. An attacker can set an arbitrary value except 'NO' to the login cookie and have full system access.
References
Configurations
No configuration.
History
21 Nov 2024, 09:30
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cisa.gov/news-events/ics-advisories/icsa-24-107-02 - |
28 May 2024, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) Electrolink transmitters are vulnerable to an authentication bypass vulnerability affecting the login cookie. An attacker can set an arbitrary value except 'NO' to the login cookie and have full system access. |
Information
Published : 2024-04-18 22:15
Updated : 2024-11-21 09:30
NVD link : CVE-2024-3741
Mitre link : CVE-2024-3741
CVE.ORG link : CVE-2024-3741
JSON object : View
Products Affected
No product.
CWE
CWE-302
Authentication Bypass by Assumed-Immutable Data