Improper Access Control leads to adding a high-privilege user affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting user's role within the admin profile. An attack could occur over the public Internet in some cases.
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
Link | Tags |
---|---|
http://elenos.com | product |
https://strik3r.gitbook.io/strik3r-blog/security-research/cves-pocs/cve-2023-34672 | third party advisory exploit |