Multiple vulnerabilities in Geutebrck G-Cam E2 and G-Code

Published: 2021-07-28


Risk
High
Patch available
YES
Number of vulnerabilities
12
CVE ID
CVE-2021-33543CVE-2021-33544CVE-2021-33545CVE-2021-33546CVE-2021-33547CVE-2021-33548CVE-2021-33549CVE-2021-33550CVE-2021-33551CVE-2021-33552CVE-2021-33553CVE-2021-33554
CWE ID
CWE-306CWE-77CWE-121
Exploitation vector
Network
Public exploit
N/A
Vulnerable softwareSubscribe
G-Cam E2Hardware solutions / Firmware

G-CodeHardware solutions / Firmware


Vendor
GEUTEBRÜCK GmbH

Security Advisory



1) Missing Authentication for Critical Function


Risk: High


CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C] [PCI]


CVE-ID: CVE-2021-33543


CWE-ID: CWE-306 - Missing Authentication for Critical Function


Exploit availability: No


Description

The vulnerability allows a remote attacker to bypass authentication process.


The vulnerability exists due to default user authentication settings. A remote attacker can gain access to sensitive files and gain access to the target system.


This vulnerability affects t ..

Support the originator by clicking the read the rest link below.