An issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers to login as any user without a password.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
https://github.com/PostalBlab/Vulnerabilities/blob/main/ComScale/auth_bypass.txt | third party advisory exploit |
https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2023-45911 |