CVE-2023-50707

Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service condition on the device.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-353-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:efacec:bcu_500_firmware:4.07:*:*:*:*:*:*:*
cpe:2.3:h:efacec:bcu_500:-:*:*:*:*:*:*:*

History

29 Dec 2023, 16:19

Type Values Removed Values Added
Summary
  • (es) Mediante la explotación de sesiones de usuarios activos, un atacante podría enviar solicitudes personalizadas para provocar una condición de denegación de servicio en el dispositivo.
First Time Efacec bcu 500
Efacec bcu 500 Firmware
Efacec
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-353-02 - () https://www.cisa.gov/news-events/ics-advisories/icsa-23-353-02 - Third Party Advisory, US Government Resource
CVSS v2 : unknown
v3 : 9.6
v2 : unknown
v3 : 7.5
CPE cpe:2.3:o:efacec:bcu_500_firmware:4.07:*:*:*:*:*:*:*
cpe:2.3:h:efacec:bcu_500:-:*:*:*:*:*:*:*

20 Dec 2023, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-20 00:15

Updated : 2023-12-29 16:19


NVD link : CVE-2023-50707

Mitre link : CVE-2023-50707

CVE.ORG link : CVE-2023-50707


JSON object : View

Products Affected

efacec

  • bcu_500
  • bcu_500_firmware
CWE
CWE-400

Uncontrolled Resource Consumption