cve/2023/CVE-2023-6930.md

18 lines
798 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2023-6930](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6930)
![](https://img.shields.io/static/v1?label=Product&message=ETL3100&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20v01c01%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=%20CWE-284%20Improper%20Access%20Control&color=brighgreen)
### Description
EuroTel ETL3100 versions v01c01 and v01x37 suffer from an unauthenticated configuration and log download vulnerability. This enables the attacker to disclose sensitive information and assist in authentication bypass, privilege escalation, and full system access.
### POC
#### Reference
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-353-05
#### Github
No PoCs found on GitHub currently.