Fiche vulnérabilité
CVE-2023-28718 : faille élevée propumpservice osprey pump controller… (CVSS 8.0)
Description
Osprey Pump Controller version 1.01 allows users to perform certain actions via HTTP requests without performing any checks to verify the requests. This may allow an attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.
En bref
- Sévérité
- Élevée (CVSS 8.0)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 28 mars 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- propumpservice osprey pump controller firmware