Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Solution:
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-109-05 | third party advisory us government resource |