Osprey Pump Controller version 1.01 allows users to perform certain actions via HTTP requests without performing any checks to verify the requests. This may allow an attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.
History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T21:37:47.648Z

Reserved: 2023-03-21T21:17:06.902Z

Link: CVE-2023-28718

cve-icon Vulnrichment

Updated: 2024-08-02T13:43:23.859Z

cve-icon NVD

Status : Modified

Published: 2023-03-28T21:15:11.587

Modified: 2024-11-21T07:55:52.073

Link: CVE-2023-28718

cve-icon Redhat

No data.