Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, thereby gaining unauthorized access to the system. A threat actor could exploit this vulnerability to create a user account without providing valid credentials. A threat actor who successfully exploits this vulnerability could gain access to the pump controller and cause disruption in operation, modify data, or shut down the controller.
History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T21:37:57.274Z

Reserved: 2023-03-21T21:17:06.897Z

Link: CVE-2023-28398

cve-icon Vulnrichment

Updated: 2024-08-02T12:38:25.301Z

cve-icon NVD

Status : Modified

Published: 2023-03-28T21:15:11.003

Modified: 2024-11-21T07:54:59.510

Link: CVE-2023-28398

cve-icon Redhat

No data.