A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including information exposures, denial of service, and arbitrary code execution when access control checks are not applied consistently.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://www.se.com/ww/en/download/document/SEVD-2020-315-06/ | vendor advisory |
https://us-cert.cisa.gov/ics/advisories/icsa-20-343-03 | third party advisory |