Circutor SGE-PLC1000 improper authentication
Vulnerability Description
Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware version 0.9.2b allows an attacker to perform operations as an authenticated user. In order to exploit this vulnerability, the attacker must be within the network where the device affected is located.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-33842
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Industrial Cybersecurity team of S21sec, special mention to Aarón Flecha Menéndez.
References
More from Circutor
View All →Affected Vendor
Circutor
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.